CVE-2020-28209
Last modified
CVE-2020-28209 is a high-severity vulnerability rated 7/10 on the CVSS scale. A CWE-428 Windows Unquoted Search Path vulnerability exists in EcoStruxure Building Operation Enterprise Server installer V1.9 - V3.1 and Enterprise Central installer V2.0 - V3.1 that could cause any local Windows user who has write permission on at least one of the subfolders of the Connect Agent service binary path, being able to gain the privilege of the user who started the service. By default, the Enterprise Server and Enterprise Central is always installed at a location requiring Administrator privileges so the vulnerability is only valid if the application has been installed on a non-secure location.. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
A CWE-428 Windows Unquoted Search Path vulnerability exists in EcoStruxure Building Operation Enterprise Server installer V1.9 - V3.1 and Enterprise Central installer V2.0 - V3.1 that could cause any local Windows user who has write permission on at least one of the subfolders of the Connect Agent service binary path, being able to gain the privilege of the user who started the service. By default, the Enterprise Server and Enterprise Central is always installed at a location requiring Administrator privileges so the vulnerability is only valid if the application has been installed on a non-secure location.
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Enterprise Server Installer | >= 1.9, <= 3.1 |
References
- https://www.se.com/ww/en/download/document/SEVD-2020-315-04/Patch, Product, Vendor Advisory
- https://www.se.com/ww/en/download/document/SEVD-2020-315-04/Patch, Product, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-28209?
How severe is CVE-2020-28209?
How do I fix CVE-2020-28209?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-28199best it Amazon Pay Plugin before 9.4.2 for Shopware exposes …9.1
- CVE-2020-2820Vulnerability in the Oracle Common Applications Calendar pro…8.2
- CVE-2020-28200The Sieve engine in Dovecot before 2.3.15 allows Uncontrolle…4.3
- CVE-2020-28203An issue was discovered in Foxit Reader and PhantomPDF 10.1.…5.5
- CVE-2020-28206An issue was discovered in Bitrix24 Bitrix Framework (1c sit…6.5
- CVE-2020-28208An email address enumeration vulnerability exists in the pas…5.3
- CVE-2020-2821Vulnerability in the Oracle Trade Management product of Orac…8.2
- CVE-2020-28210A CWE-79 Improper Neutralization of Input During Web Page Ge…6.1
- CVE-2020-28211A CWE-863: Incorrect Authorization vulnerability exists in P…7.8
- CVE-2020-28212A CWE-307: Improper Restriction of Excessive Authentication …9.8
- CVE-2020-28213A CWE-494: Download of Code Without Integrity Check vulnerab…8.8
- CVE-2020-28214A CWE-760: Use of a One-Way Hash with a Predictable Salt vul…5.5
Are you affected by CVE-2020-28209?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
