CVE-2020-28212: Schneider Electric Ecostruxure Control Expert
Critical severity, CVSS 9.8. EPSS: 2.8% chance of exploitation in the next 30 days.
A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution when a brute force attack is done over Modbus.
Affected products
- Schneider Electric Ecostruxure Control Expert: any version
Published 2020-11-19. Last modified 2026-06-17.