PT-2020-6317 · Schneider Electric · Ecostruxure Control Expert

Published

2020-11-19

·

Updated

2022-10-03

·

CVE-2020-28212

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions EcoStruxure Control Expert (all versions)
Description The issue is related to the lack of restrictions on authentication attempts, which could allow a remote attacker to bypass the authentication procedure. This vulnerability may lead to unauthorized command execution when a brute force attack is performed over Modbus.
Recommendations For all versions, consider implementing restrictions on excessive authentication attempts to prevent brute force attacks. As a temporary workaround, restrict access to the Modbus protocol to minimize the risk of exploitation. Avoid using the PLC Simulator on EcoStruxure Control Expert until a patch is available that addresses the improper restriction of excessive authentication attempts.

Fix

Improper Restriction of Excessive Authentication Attempts

Weakness Enumeration

Related Identifiers

BDU:2021-04173
CVE-2020-28212

Affected Products

Ecostruxure Control Expert