Vulnerabilities
Vulnerable Software
Schneider-Electric:  >> Hmig5u2  Security Vulnerabilities
A CWE-20: Improper Input Validation vulnerability exists in EcoStruxure™ Operator Terminal Expert and Pro-face BLUE (version details in the notification) that could cause arbitrary code execution when the Ethernet Download feature is enable on the HMI.
CVSS Score
9.8
EPSS Score
0.009
Published
2021-01-26
A CWE-754 – Improper Check for Unusual or Exceptional Conditions vulnerability exists in Magelis HMI Panels (all versions of - HMIGTO, HMISTO, XBTGH, HMIGTU, HMIGTUX, HMISCU, HMISTU, XBTGT, XBTGT, HMIGXO, HMIGXU), which could cause a temporary freeze of the HMI when a high rate of frames is received. When the attack stops, the buffered commands are processed by the HMI panel.
CVSS Score
6.5
EPSS Score
0.003
Published
2019-09-17


Contact Us

Shodan ® - All rights reserved