A CWE-20: Improper Input Validation vulnerability exists in EcoStruxureâ„¢ Operator Terminal Expert and Pro-face BLUE (version details in the notification) that could cause arbitrary code execution when the Ethernet Download feature is enable on the HMI.
References
Link | Resource |
---|---|
https://www.se.com/ww/en/download/document/SEVD-2021-012-01/ | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Information
Published : 2021-01-26 10:15
Updated : 2021-02-12 11:21
NVD link : CVE-2020-28221
Mitre link : CVE-2020-28221
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
schneider-electric
- hmi_sto_532
- sp-5600wa
- hmist6200
- hmist6700
- gp-4107g
- gp-4106w
- hmi_sto_501
- hmi_sto_511
- gp-4107w
- pro-face_blue
- hmi_sto_531
- ecostruxure_operator_terminal_expert
- sp-5700wc
- sp-5b10
- sp-5b00
- st-6600wa
- sp-5400wa
- hmig3u
- hmig3x
- st-6200wa
- st-6700wa
- gp-4104g
- hmi_sto_512
- sp-5500wa
- sp-5800wc
- gp-4106g
- hmig5u
- hmist6400
- sp-5b41
- sp-5660tp
- st-6400wa
- hmist6600
- gp-4105g
- st-6500wa
- hmist6500
- sp-5700tp
- hmig5u2
- sp-5500tp
- sp-5600ta
- gp-4104w
- gp-4105w
- sp-5600tp