VDB

SEVD-2020-315-02

SEVD-2020-315-02 PUBLISHED CVSS 7.400000095367432 HIGH

Schneider Electric is aware of a vulnerability in its EcoStruxure™ Operator Terminal Expert (formerly known as Vijeo XD), Pro-face BLUE and WinGP runtimes. This vulnerability impacts Windows PC and Harmony iPC offers. The EcoStruxure™ Operator Terminal Expert and Pro-face BLUE products are HMI configuration software supporting gestures and UI designs. WinGP is a runtime engine on Windows PC and is included in Pro-face GP-Pro EX product which is an HMI Screen Editor & Logic Programming Software for Pro-face. Failure to apply the remediations provided below may risk unauthorized command execution by a local user of the Windows engineering workstation, which could result in loss of availability, confidentiality and integrity of the workstation where EcoStruxure™ Operator Terminal Expert , Pro-face BLUE or WinGP runtime is installed. January 2021 update: Added Pro-face BLUE and WinGP to the list of products affected and links to the fixes

Risk Scores

CVSS 3.1
7.400000095367432
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Schneider Electric EcoStruxure™ Operator Terminal Expert V3.1 Service Pack 1B
Schneider Electric WinGP installed on Pro-face PS4000 & PS5000 series and SP-5B40, SP5B41 using legacy BIOS V4.09.120 and prior
Schneider Electric Pro-face BLUE Runtime installed on Pro-face iPC (SP-5B10) using legacy BIOS 3.1 Service Pack 1A and prior
Schneider Electric WinGP V4.09.200
Schneider Electric EcoStruxure™ Operator Terminal Expert Runtime installed on Harmony iPC(HMIG3U) using legacy BIOS 3.1 Service Pack 1A and prior
Schneider Electric Pro-face BLUE Runtime installed on Windows PC using legacy BIOS 3.1 Service Pack 1A and prior
Schneider Electric WinGP installed on Windows PC using legacy BIOS V4.09.120 and prior
Schneider Electric Pro-face BLUE V3.1 Service Pack 1B
Schneider Electric EcoStruxure™ Operator Terminal Expert Runtime installed on Windows PC using legacy BIOS 3.1 Service Pack 1A and prior

Timeline

  • Nov 9, 2020 CVE Published
  • Jan 11, 2021 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›