7.8
CVE-2020-7585
- EPSS 0.09%
- Published 10.06.2020 17:15:12
- Last modified 21.11.2024 05:37:25
- Source productcert@siemens.com
- Teams watchlist Login
- Open Login
A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3), SIMATIC PDM (All versions < V9.2), SIMATIC STEP 7 V5.X (All versions < V5.6 SP2 HF3), SINAMICS STARTER (containing STEP 7 OEM version) (All versions < V5.4 HF2). A DLL Hijacking vulnerability could allow a local attacker to execute code with elevated privileges. The security vulnerability could be exploited by an attacker with local access to the affected systems. Successful exploitation requires user privileges but no user interaction. The vulnerability could allow an attacker to compromise the availability of the system as well as to have access to confidential information.
Data is provided by the National Vulnerability Database (NVD)
Siemens ≫ Simatic Step 7 Version < 5.6
Siemens ≫ Simatic Step 7 Version5.6 Update-
Siemens ≫ Simatic Step 7 Version5.6 Updatesp1
Siemens ≫ Simatic Step 7 Version5.6 Updatesp2
Siemens ≫ Simatic Step 7 Version5.6 Updatesp2_hotfix1
Siemens ≫ Sinamics Starter Version < 5.4
Siemens ≫ Sinamics Starter Version5.4 Update-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.09% | 0.259 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
CWE-427 Uncontrolled Search Path Element
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.