CVE-2020-25238

Scores

EPSS

0.000none0.0%
0%20%40%60%80%100%

Percentile: 0.0%

CVSS

7.8high3.x
0246810

CVSS Score: 7.8/10

All CVSS Scores

CVSS 3.x
7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS 2.0
7.2

Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Description

A vulnerability has been identified in PCS neo (Administration Console) (All versions < V3.1), TIA Portal (V15, V15.1 and V16). Manipulating certain files in specific folders could allow a local attacker to execute code with SYSTEM privileges. The security vulnerability could be exploited by an attacker with a valid account and limited access rights on the system.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-284

Recommendations

Source: nvd

Apply an updateThis issue is addressed in TIA Administrator V1.0 SP2 Upd2. PCS neo administration console users should apply the mitigations described in Industrial Security in SIMATIC PCS neo.For more details see Siemens Security Advisory SSA-428051.

URL: https://www.kb.cert.org/vuls/id/466044

Vulnerable Software (2)

Type: Configuration

Vendor: siemens

Product: simatic_process_control_system_neo

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:siemens:simatic_process_control_system_neo:*:*:*:*:*:*:*:*",      "versionEndExcluding": "3.1",      "vulnerable": true    },    {      "cpe2...

Source: nvd

Type: Configuration

Vendor: siemens

Product: totally_integrated_automation_portal

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:siemens:simatic_process_control_system_neo:*:*:*:*:*:*:*:*",      "versionEndExcluding": "3.1",      "vulnerable": true    },    {      "cpe2...

Source: nvd