← Vulnerability feed

Vulnerability record · CVE-2020-28219 · published 11 December 2020

CVE-2020-28219: Schneider-electric ecostruxure geo scada expert 2019 insufficiently protected credentials vulnerability

Schneider Electric · Ecostruxure Geo Scada Expert 2019

A CWE-522: Insufficiently Protected Credentials vulnerability exists in EcoStruxure Geo SCADA Expert 2019 (Original release and Monthly Updates to September 2020, from 81.7268.1 to 81.7578.1) and EcoStruxure Geo SCADA Expert 2020 (Original release and Monthly Updates to September 2020, from 83.7551.1 to 83.7578.1), that could cause exposure of credentials to server-side users when web users are logged in to Virtual ViewX.

7.8 CVSS 3.1 High EPSS 0.31% · top 78.5% CWE-522 · Insufficiently protected credentials
7.8CVSS 3.1 base score, v2 2.1
0.31%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A CWE-522: Insufficiently Protected Credentials vulnerability exists in EcoStruxure Geo SCADA Expert 2019 (Original release and Monthly Updates to September 2020, from 81.7268.1 to 81.7578.1) and EcoStruxure Geo SCADA Expert 2020 (Original release and Monthly Updates to September 2020, from 83.7551.1 to 83.7578.1), that could cause exposure of credentials to server-side users when web users are logged in to Virtual ViewX.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-28219 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-22610Schneider-electric ecostruxure geo scada expert 2019 incorrect authorization vulnerabilityA CWE-863: Incorrect Authorization vulnerability exists that could cause Denial of Service against the Geo SCADA server when specific messages are se…EPSS 0.57%7.5CVE-2023-22611Schneider-electric ecostruxure geo scada expert 2019 information exposure vulnerabilityA CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause information disclosure when specific mess…EPSS 0.57%7.5CVE-2022-24318Schneider-electric clearscada inadequate encryption strength vulnerabilityA CWE-326: Inadequate Encryption Strength vulnerability exists that could cause non-encrypted communication with the server when outdated versions of…EPSS 0.39%7.5CVE-2022-24321Schneider-electric clearscada vulnerabilityA CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause Denial of Service against the Geo SCADA server …EPSS 1.00%6.7CVE-2021-22741Schneider-electric clearscada vulnerabilityUse of Password Hash with Insufficient Computational Effort vulnerability exists in ClearSCADA (all versions), EcoStruxure Geo SCADA Expert 2019 (all…EPSS 0.17%5.9CVE-2022-24319Schneider-electric clearscada improper certificate validation vulnerabilityA CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and…EPSS 0.58%5.9CVE-2022-24320Schneider-electric clearscada improper certificate validation vulnerabilityA CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and…EPSS 0.54%5.3CVE-2023-0595Schneider-electric clearscada vulnerabilityA CWE-117: Improper Output Neutralization for Logs vulnerability exists that could cause the misinterpretation of log files when malicious packets ar…EPSS 0.42%

Source: NIST National Vulnerability Database (record CVE-2020-28219), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.