CVE-2020-28221

Publication date

2021-01-25 17:08:37

Family

schneider

State

PUBLISHED

Description

A CWE-20: Improper Input Validation vulnerability exists in EcoStruxureâ„¢ Operator Terminal Expert and Pro-face BLUE (version details in the notification) that could cause arbitrary code execution when the Ethernet Download feature is enable on the HMI.