PT-2021-3891 · Schneider Electric · Pro-Face Blue+1

Published

2021-01-12

·

Updated

2021-02-12

·

CVE-2020-28221

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions EcoStruxure Operator Terminal Expert (affected versions not specified) Pro-face BLUE (affected versions not specified)
Description The issue is related to insufficient input validation in the Ethernet Download feature of the affected software, which could allow a remote attacker to execute arbitrary code. This is due to a CWE-20: Improper Input Validation vulnerability.
Recommendations For EcoStruxure Operator Terminal Expert, disable the Ethernet Download feature until a patch is available. For Pro-face BLUE, restrict access to the Ethernet Download feature to minimize the risk of exploitation. As a temporary workaround, consider disabling the Ethernet Download feature on both products until a patch is available.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04273
CVE-2020-28221

Affected Products

Ecostruxure Operator Terminal Expert
Pro-Face Blue