EcoStruxure™ Operator Terminal Expert and Pro-face BLUE
Schneider Electric has identified multiple vulnerabilities in EcoStruxure Operator Terminal Expert and Pro-face BLUE HMI configuration software affecting versions prior to 3.3. These vulnerabilities (CWE-347, CWE-22, CWE-704, CWE-89) include path traversal, certificate/signature validation bypass, incorrect type conversion, and SQL injection. A local user with access to a Windows engineering workstation can exploit these flaws to execute arbitrary code with the privileges of the workstation user, potentially allowing modification of HMI configurations before deployment to control systems, resulting in loss of availability, integrity, and confidentiality.
- Local access to Windows engineering workstation
- User account with permissions to run EcoStruxure Operator Terminal Expert or Pro-face BLUE
- Software must be installed and running on the workstation
Patching may require device reboot — plan for process interruption
/api/v1/advisories/e05c4d60-5829-424a-b998-816e6cd99fe0Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.