← Vulnerability feed

Vulnerability record · CVE-2020-28212 · published 19 November 2020

CVE-2020-28212: Schneider-electric ecostruxure control expert improper restriction of authentication attempts vulnerability

Schneider Electric · Ecostruxure Control Expert

A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution when a brute force attack is done over Modbus.

9.8 CVSS 3.1 Critical EPSS 2.8% · top 14.3% CWE-307 · Improper restriction of authentication attempts
9.8CVSS 3.1 base score, v2 7.5
2.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution when a brute force attack is done over Modbus.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-28212 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-45789Schneider-electric ecostruxure control expert authentication bypass by capture-replay vulnerabilityA CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the controller…EPSS 1.5%9.8CVE-2022-45788Schneider-electric ecostruxure control expert vulnerabilityA CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code execution, denial of service and…EPSS 1.2%9.8CVE-2022-37300Schneider-electric ecostruxure control expert weak password recovery vulnerabilityA CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized access in read and write mode t…EPSS 0.75%9.8CVE-2022-26507Att xmill out-of-bounds write vulnerabilityA heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file can lead to remote code executi…EPSS 2.4%9.8CVE-2020-7475Schneider-electric ecostruxure control expert injection vulnerabilityA CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), reflective DLL, vulnerability exists in…EPSS 1.6%9.1CVE-2021-22779Schneider-electric ecostruxure control expert authentication bypass by spoofing vulnerabilityAuthentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unit…EPSS 1.0%8.8CVE-2023-27976Schneider-electric ecostruxure control expert exposure of resource to wrong sphere vulnerabilityA CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause remote code execution when a valid user visits a malicious link…EPSS 0.85%8.8CVE-2020-28213Schneider-electric ecostruxure control expert download of code without integrity check vulnerabilityA CWE-494: Download of Code Without Integrity Check vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all version…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2020-28212), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.