MEDIUM · 6.7

CVE-2020-7581

A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcenter Execution Process (All versions < V3.2), Opcente...

Vulnerability Description

A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcenter Execution Process (All versions < V3.2), Opcenter Intelligence (All versions < V3.3), Opcenter Quality (All versions < V11.3), Opcenter RD&L (V8.0), SIMATIC Notifier Server for Windows (All versions), SIMATIC PCS neo (All versions < V3.0 SP1), SIMATIC STEP 7 (TIA Portal) V15 (All versions < V15.1 Update 5), SIMATIC STEP 7 (TIA Portal) V16 (All versions < V16 Update 2), SIMOCODE ES V15.1 (All versions < V15.1 Update 4), SIMOCODE ES V16 (All versions < V16 Update 1), Soft Starter ES V15.1 (All versions < V15.1 Update 3), Soft Starter ES V16 (All versions < V16 Update 1). A component within the affected application calls a helper binary with SYSTEM privileges during startup while the call path is not quoted. This could allow a local attacker with administrative privileges to execute code with SYSTEM level privileges.

CVSS Score

6.7

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
SiemensOpcenter Execution Discrete< 3.2
SiemensOpcenter Execution Foundation< 3.2
SiemensOpcenter Execution Process< 3.2
SiemensOpcenter IntelligenceAll versions
SiemensOpcenter Quality< 11.3
SiemensOpcenter Rd\&L8.0
SiemensSimatic Notifier ServerAll versions
SiemensSimatic Pcs NeoAll versions
SiemensSimatic Step 7< 16
SiemensSimocode EsAll versions
SiemensSoft Starter EsAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-7581?

CVE-2020-7581 is a vulnerability with a CVSS score of 6.7 (MEDIUM). A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcenter Execution Process (All versions < V3.2), Opcente...

How severe is CVE-2020-7581?

CVE-2020-7581 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-7581?

Check the references section above for vendor advisories and patch information. Affected products include: Siemens Opcenter Execution Discrete, Siemens Opcenter Execution Foundation, Siemens Opcenter Execution Process, Siemens Opcenter Intelligence, Siemens Opcenter Quality.