HIGH · 8.2

CVE-2020-7587

A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcenter Execution Process (All versions < V3.2), Opcente...

Vulnerability Description

A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcenter Execution Process (All versions < V3.2), Opcenter Intelligence (All versions < V3.3), Opcenter Quality (All versions < V11.3), Opcenter RD&L (V8.0), SIMATIC IT LMS (All versions < V2.6), SIMATIC IT Production Suite (All versions < V8.0), SIMATIC Notifier Server for Windows (All versions), SIMATIC PCS neo (All versions < V3.0 SP1), SIMATIC STEP 7 (TIA Portal) V15 (All versions < V15.1 Update 5), SIMATIC STEP 7 (TIA Portal) V16 (All versions < V16 Update 2), SIMOCODE ES V15.1 (All versions < V15.1 Update 4), SIMOCODE ES V16 (All versions < V16 Update 1), Soft Starter ES V15.1 (All versions < V15.1 Update 3), Soft Starter ES V16 (All versions < V16 Update 1). Sending multiple specially crafted packets to the affected service could cause a partial remote denial-of-service, that would cause the service to restart itself. On some cases the vulnerability could leak random information from the remote service.

CVSS Score

8.2

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
LOW

Affected Products

VendorProductVersions
SiemensOpcenter Execution Discrete< 3.2
SiemensOpcenter Execution Foundation< 3.2
SiemensOpcenter Execution Process< 3.2
SiemensOpcenter Intelligence< 3.3
SiemensOpcenter Quality< 11.3
SiemensOpcenter Rd\&L8.0
SiemensSimatic It Lms< 2.6
SiemensSimatic It Production Suite< 8.0
SiemensSimatic Notifier ServerAll versions
SiemensSimatic Pcs Neo< 3.0
SiemensSimatic Step 7>= 15, < 15.1
SiemensSimocode Es< 15.1
SiemensSoft Starter Es< 15.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-7587?

CVE-2020-7587 is a vulnerability with a CVSS score of 8.2 (HIGH). A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcenter Execution Process (All versions < V3.2), Opcente...

How severe is CVE-2020-7587?

CVE-2020-7587 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-7587?

Check the references section above for vendor advisories and patch information. Affected products include: Siemens Opcenter Execution Discrete, Siemens Opcenter Execution Foundation, Siemens Opcenter Execution Process, Siemens Opcenter Intelligence, Siemens Opcenter Quality.