IM
IronMonkey Threat Research

CVE-2020-28209 HIGH

Published: 2020-11-19 | Last Modified: 2026-05-28 | Status: Modified

Description

A CWE-428 Windows Unquoted Search Path vulnerability exists in EcoStruxure Building Operation Enterprise Server installer V1.9 - V3.1 and Enterprise Central installer V2.0 - V3.1 that could cause any local Windows user who has write permission on at least one of the subfolders of the Connect Agent service binary path, being able to gain the privilege of the user who started the service. By default, the Enterprise Server and Enterprise Central is always installed at a location requiring Administrator privileges so the vulnerability is only valid if the application has been installed on a non-secure location.

Additional Descriptions (1)

Se presenta una vulnerabilidad de Ruta de Búsqueda sin Comillas de Windows CWE-428 en el instalador de EcoStruxure Building Operation Enterprise Server versiones V1.9 - V3.1 y el instalador de Enterprise Central versiones V2.0 - V3.1 que podría causar que cualquier usuario de Windows local que tenga permiso de escritura en al menos uno de las subcarpetas de la ruta binaria del servicio Connect Agent, sea capaz de alcanzar el privilegio del usuario que inició el servicio. Por defecto, Enterprise Server y Enterprise Central siempre se instalan en una ubicación que requiere privilegios de administrador, por lo que la vulnerabilidad solo es válida si la aplicación se ha instalado en una ubicación no segura

CVSS Metrics

Base Score: 7.0 (HIGH)

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack VectorLOCAL
Attack ComplexityHIGH
Privileges RequiredLOW
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 1.0

Impact Score: 5.9

Base Score: 4.4 (MEDIUM)

AV:L/AC:M/Au:N/C:P/I:P/A:P

Access VectorLOCAL
Access ComplexityMEDIUM
AuthenticationNONE
Confidentiality ImpactPARTIAL
Integrity ImpactPARTIAL
Availability ImpactPARTIAL

Source: [email protected]

Type: Primary

Exploitability Score: 3.4

Impact Score: 6.4

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-428

Affected Products

Vendor Product Version Update Type
schneider-electric enterprise_server_installer * <built-in method update of dict object at 0x7e6107fb64c0> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:schneider-electric:enterprise_server_installer:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

References

Notification
Message here