← Back

CVE-2020-7580

nvd nist
Published: Jun 10, 2020Modified: Jun 17, 2026

JSON object

Loading...
6.7
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: NVD

Description

A vulnerability has been identified in SIMATIC Automation Tool (All versions < V4 SP2), SIMATIC NET PC Software V14 (All versions < V14 SP1 Update 14), SIMATIC NET PC Software V15 (All versions), SIMATIC NET PC Software V16 (All versions < V16 Upd3), SIMATIC PCS neo (All versions < V3.0 SP1), SIMATIC ProSave (All versions < V17), SIMATIC S7-1500 Software Controller (All versions < V21.8), SIMATIC STEP 7 (TIA Portal) V13 (All versions < V13 SP2 Update 4), SIMATIC STEP 7 (TIA Portal) V14 (All versions < V14 SP1 Update 10), SIMATIC STEP 7 (TIA Portal) V15 (All versions < V15.1 Update 5), SIMATIC STEP 7 (TIA Portal) V16 (All versions < V16 Update 2), SIMATIC STEP 7 V5 (All versions < V5.6 SP2 HF3), SIMATIC WinCC OA V3.16 (All versions < V3.16 P018), SIMATIC WinCC OA V3.17 (All versions < V3.17 P003), SIMATIC WinCC Runtime Advanced (All versions < V16 Update 2), SIMATIC WinCC Runtime Professional V13 (All versions < V13 SP2 Update 4), SIMATIC WinCC Runtime Professional V14 (All versions < V14 SP1 Update 10), SIMATIC WinCC Runtime Professional V15 (All versions < V15.1 Update 5), SIMATIC WinCC Runtime Professional V16 (All versions < V16 Update 2), SIMATIC WinCC V7.4 (All versions < V7.4 SP1 Update 14), SIMATIC WinCC V7.5 (All versions < V7.5 SP1 Update 3), SINAMICS STARTER (All Versions < V5.4 HF2), SINAMICS Startdrive (All Versions < V16 Update 3), SINEC NMS (All versions < V1.0 SP2), SINEMA Server (All versions < V14 SP3), SINUMERIK ONE virtual (All Versions < V6.14), SINUMERIK Operate (All Versions < V6.14). A common component used by the affected applications regularly calls a helper binary with SYSTEM privileges while the call path is not quoted. This could allow a local attacker to execute arbitrary code with SYTEM privileges.

Affected (44)

17 products
Simatic Automatic Tool
Simatic Net Pc
Simatic Pcs 7
Simatic Pcs Neo
Simatic Prosave
Simatic Step 7
Simatic Wincc
Simatic Wincc Open Architecture
Simatic Wincc Runtime Advanced
Sinamics Startdrive
Sinec Network Management System
Sinema Server
Sinumerik One Virtual
Sinumerik Operate
Configuration A
44 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Siemens
Before 16
Version 16
Version 16 update1
All versions
All versions
All versions
Before 21.8
Siemens
Before 5.6
From 13 to 16
Version 5.6
Version 5.6 sp1
Version 5.6 sp2
Version 5.6 sp2_hotfix1
Siemens
Before 7.4
Version 7.4
Version 7.4 sp1
Version 7.4 sp1_update10
Version 7.4 sp1_update11
Version 7.4 sp1_update12
Version 7.4 sp1_update13
Version 7.4 sp1_update1
Version 7.4 sp1_update2
Version 7.4 sp1_update3
Version 7.4 sp1_update4
Version 7.4 sp1_update5
Version 7.4 sp1_update6
Version 7.4 sp1_update7
Version 7.4 sp1_update8
Version 7.4 sp1_update9
Version 7.5
Version 7.5 sp1
Version 7.5 sp1_update1
Version 7.5 sp1_update2
Siemens
Version 3.16
Version 3.17
All versions
From 13 to 16
All versions
All versions
All versions
All versions
All versions
All versions

References (4)

Source: productcert@siemens.com
Vendor Advisory
Source: productcert@siemens.com
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.