PT-2020-6317 · Schneider Electric · Ecostruxure Control Expert

CVE-2020-28212

·

Published

2020-11-19

·

Updated

2022-10-03

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions EcoStruxure Control Expert (all versions)
Description The issue is related to the lack of restrictions on authentication attempts, which could allow a remote attacker to bypass the authentication procedure. This vulnerability may lead to unauthorized command execution when a brute force attack is performed over Modbus.
Recommendations For all versions, consider implementing restrictions on excessive authentication attempts to prevent brute force attacks. As a temporary workaround, restrict access to the Modbus protocol to minimize the risk of exploitation. Avoid using the PLC Simulator on EcoStruxure Control Expert until a patch is available that addresses the improper restriction of excessive authentication attempts.

Fix

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04173
CVE-2020-28212

Affected Products

Ecostruxure Control Expert