CVE-2020-28219: Schneider Electric Ecostruxure Geo Scada Expert 2019

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

A CWE-522: Insufficiently Protected Credentials vulnerability exists in EcoStruxure Geo SCADA Expert 2019 (Original release and Monthly Updates to September 2020, from 81.7268.1 to 81.7578.1) and EcoStruxure Geo SCADA Expert 2020 (Original release and Monthly Updates to September 2020, from 83.7551.1 to 83.7578.1), that could cause exposure of credentials to server-side users when web users are logged in to Virtual ViewX.

Affected products

  • Schneider Electric Ecostruxure Geo Scada Expert 2019: from 81.7268.1, up to and including 81.7578.1
  • Schneider Electric Ecostruxure Geo Scada Expert 2020: from 83.7551.1, up to and including 83.7578.1

Published 2020-12-11. Last modified 2026-06-17.