Unquoted Search Path or Element in EcoStruxure Building Operation Enterprise Server installer and EcoStruxure Building Operation Enterprise Central installer - CVE-2020-28209

 

Unquoted Search Path or Element in EcoStruxure Building Operation Enterprise Server installer and EcoStruxure Building Operation Enterprise Central installer - CVE-2020-28209

Published: March 8, 2021


Vulnerability identifier: #VU51258
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-28209
CWE-ID: CWE-428
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to compromise the target system.

The vulnerability exists due to an unquoted search path issue. A local administrator can gain the privilege of the user who started the service.


Affected software

EcoStruxure Building Operation Enterprise Server installer
EcoStruxure Building Operation Enterprise Central installer

How to mitigate CVE-2020-28209

Install updates from vendor's website.

EcoStruxure Building Operation Enterprise Server installer - update to 3.2
EcoStruxure Building Operation Enterprise Central installer - update to 3.2

External References

Related Security Bulletins