Unquoted Search Path or Element in EcoStruxure Building Operation Enterprise Server installer and EcoStruxure Building Operation Enterprise Central installer - CVE-2020-28209
Published: March 8, 2021
Vulnerability identifier: #VU51258
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-28209
CWE-ID: CWE-428
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to compromise the target system.
The vulnerability exists due to an unquoted search path issue. A local administrator can gain the privilege of the user who started the service.
Affected software
EcoStruxure Building Operation Enterprise Server installer
EcoStruxure Building Operation Enterprise Central installer
EcoStruxure Building Operation Enterprise Central installer
How to mitigate CVE-2020-28209
Install updates from vendor's website.
EcoStruxure Building Operation Enterprise Server installer - update to 3.2
EcoStruxure Building Operation Enterprise Central installer - update to 3.2
EcoStruxure Building Operation Enterprise Central installer - update to 3.2