LiveActive security incident?Get immediate response
CVE Record

CVE-2020-7571: A CWE-79 Multiple Improper Neutralization of Input During Web Page Generation (Cross-site Scripting Reflect...

A CWE-79 Multiple Improper Neutralization of Input During Web Page Generation (Cross-site Scripting Reflected) vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause a remote attacker to inject arbitrary web script or HTML due to incorrect sanitization of user supplied data and achieve a Cross-Site Scripting reflected attack against other WebReport users.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This vulnerability affects Schneider Electric EcoStruxure Building Operation WebReports versions 1.9 through 3.1. A remote attacker could cause a WebReports user to run attacker-controlled script or HTML in their browser. The source bundle does not provide CVSS, patch details, or evidence of active exploitation.

Executive priority

Treat this as a moderate-priority application security issue, especially in building operations environments. It is not documented here as actively exploited, but successful abuse could affect trusted WebReports users and potentially support broader compromise through their sessions.

Technical view

CVE-2020-7571 is a reflected cross-site scripting issue classified as CWE-79. The flaw is incorrect sanitization of user-supplied data during web page generation in EcoStruxure Building Operation WebReports V1.9-V3.1. Impact depends on user interaction, session privileges, and how WebReports is exposed.

Likely exposure

Exposure is limited to organizations running EcoStruxure Building Operation WebReports V1.9 through V3.1. Risk is higher where WebReports is reachable by many users, remote users, or less-trusted networks. The bundle does not identify other affected products or CPEs.

Exploitation context

The CVE describes remote reflected XSS against other WebReport users. CISA KEV status is false in the bundle, and no cited source here states active exploitation. No exploit availability, prerequisites, or attacker workflow are provided.

Researcher notes

The public bundle is sparse: no CVSS vector, no detailed version matrix beyond V1.9-V3.1, no patch text, and no exploitation evidence. Avoid expanding scope beyond EcoStruxure Building Operation WebReports unless confirmed in Schneider guidance.

Mitigation direction

  • Identify all EcoStruxure Building Operation WebReports deployments and versions.
  • Review Schneider Electric advisory SEVD-2020-315-04 for vendor remediation guidance.
  • Limit WebReports access to trusted users and networks where feasible.
  • Prioritize remediation for internet-reachable or broadly accessible WebReports instances.
  • Monitor for suspicious links or unusual WebReports user activity.

Validation and detection

  • Confirm whether WebReports V1.9 through V3.1 exists in the environment.
  • Check whether WebReports is externally reachable or broadly internally accessible.
  • Review vendor advisory details before selecting upgrade or mitigation actions.
  • Assess whether affected WebReports users have privileged building-management access.
  • Document compensating controls if vendor remediation cannot be applied promptly.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-79: User-session and phishing behavior lookup

Client-side and session-facing weaknesses should be reviewed alongside initial-access and user-execution behaviors. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2020-7571 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/aEcoStruxure Building Operation WebReports V1.9 - V3.1EcoStruxure Building Operation WebReports V1.9 - V3.1Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-79 · source CWE mapping

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.