Publisher not identified
EcoStruxure Geo SCADA Expert 2019 (Original release and Monthly Updates to September 2020, from 81.7268.1 to 81.7578.1) and EcoStruxure Geo SCADA Expert 2020 (Original release and Monthly Updates to September 2020, from 83.7551.1 to 83.7578.1)
Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.
This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.
A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.
CVE-observed version history
| CVE | Published | Affected versions | Fixed version information | Publisher evidence |
|---|---|---|---|---|
| CVE-2020-28219 | 11 Dec 2020 | EcoStruxure Geo SCADA Expert 2019 (Original release and Monthly Updates to September 2020, from 81.7268.1 to 81.7578.1) and EcoStruxure Geo SCADA Expert 2020 (Original release and Monthly Updates to September 2020, from 83.7551.1 to 83.7578.1) | The Monthly Updates from October 2020, 81.7613.1 include a fix for this vulnerability. Software is available for download here: https://tprojects.schneiderelectric.com/telemetry/display/CS/Geo+SCADA+Expert+Downloads. If Virtual ViewX is on a separate server from the Geo SCADA Server, then only Virtual ViewX software requires installation, although it is recommended to keep both up to date. If on the same server as the Geo SCADA Server then both components require update. Software updates may require reboots as requested. This software update makes changes to the Virtual ViewX settings which can be performed manually. To do this and verify that the settings are in place, refer to the mitigation steps below. Customers should use appropriate patching methodologies when applying these patches to their systems. We strongly recommend the use of back-ups and evaluating the impact of these patches in a Test and Development environment or on an offline infrastructure. Contact Schneider Electric's Customer Care Center if you need assistance removing a patch. The steps to remediate this vulnerability are automatically applied by the October Monthly Updates. | Update reference ↗ |
How this record is maintained
The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.