VYPR
Critical severity9.8NVD Advisory· Published Jan 26, 2021· Updated Jun 17, 2026

CVE-2020-28221

CVE-2020-28221

Description

A CWE-20: Improper Input Validation vulnerability exists in EcoStruxure™ Operator Terminal Expert and Pro-face BLUE (version details in the notification) that could cause arbitrary code execution when the Ethernet Download feature is enable on the HMI.

Affected products

6
  • Pro Face/BLUEllm-fuzzy
  • cpe:2.3:a:schneider-electric:ecostruxure_operator_terminal_expert:3.1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:schneider-electric:ecostruxure_operator_terminal_expert:3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:schneider-electric:ecostruxure_operator_terminal_expert:3.1:sp1a:*:*:*:*:*:*
  • cpe:2.3:a:schneider-electric:pro-face_blue:3.1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:schneider-electric:pro-face_blue:3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:schneider-electric:pro-face_blue:3.1:sp1a:*:*:*:*:*:*
  • EcoStruxure/EcoStruxure™ Operator Terminal Expert and Pro-face BLUEdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.