PT-2021-3891 · Schneider Electric · Pro-Face Blue+1
Published
2021-01-12
·
Updated
2021-02-12
·
CVE-2020-28221
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
EcoStruxure Operator Terminal Expert (affected versions not specified)
Pro-face BLUE (affected versions not specified)
Description
The issue is related to insufficient input validation in the Ethernet Download feature of the affected software, which could allow a remote attacker to execute arbitrary code. This is due to a CWE-20: Improper Input Validation vulnerability.
Recommendations
For EcoStruxure Operator Terminal Expert, disable the Ethernet Download feature until a patch is available.
For Pro-face BLUE, restrict access to the Ethernet Download feature to minimize the risk of exploitation.
As a temporary workaround, consider disabling the Ethernet Download feature on both products until a patch is available.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ecostruxure Operator Terminal Expert
Pro-Face Blue