CVE-2020-7580
Summary
| CVE | CVE-2020-7580 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-10 17:15:00 UTC |
| Updated | 2023-04-28 17:06:00 UTC |
| Description | A vulnerability has been identified in SIMATIC Automation Tool (All versions < V4 SP2), SIMATIC NET PC Software V14 (All versions < V14 SP1 Update 14), SIMATIC NET PC Software V15 (All versions), SIMATIC NET PC Software V16 (All versions < V16 Upd3), SIMATIC PCS neo (All versions < V3.0 SP1), SIMATIC ProSave (All versions < V17), SIMATIC S7-1500 Software Controller (All versions < V21.8), SIMATIC STEP 7 (TIA Portal) V13 (All versions < V13 SP2 Update 4), SIMATIC STEP 7 (TIA Portal) V14 (All versions < V14 SP1 Update 10), SIMATIC STEP 7 (TIA Portal) V15 (All versions < V15.1 Update 5), SIMATIC STEP 7 (TIA Portal) V16 (All versions < V16 Update 2), SIMATIC STEP 7 V5 (All versions < V5.6 SP2 HF3), SIMATIC WinCC OA V3.16 (All versions < V3.16 P018), SIMATIC WinCC OA V3.17 (All versions < V3.17 P003), SIMATIC WinCC Runtime Advanced (All versions < V16 Update 2), SIMATIC WinCC Runtime Professional V13 (All versions < V13 SP2 Update 4), SIMATIC WinCC Runtime Professional V14 (All versions < V14 SP1 Update 10), SIMATIC WinCC Runtime Professional V15 (All versions < V15.1 Update 5), SIMATIC WinCC Runtime Professional V16 (All versions < V16 Update 2), SIMATIC WinCC V7.4 (All versions < V7.4 SP1 Update 14), SIMATIC WinCC V7.5 (All versions < V7.5 SP1 Update 3), SINAMICS STARTER (All Versions < V5.4 HF2), SINAMICS Startdrive (All Versions < V16 Update 3), SINEC NMS (All versions < V1.0 SP2), SINEMA Server (All versions < V14 SP3), SINUMERIK ONE virtual (All Versions < V6.14), SINUMERIK Operate (All Versions < V6.14). A common component used by the affected applications regularly calls a helper binary with SYSTEM privileges while the call path is not quoted. This could allow a local attacker to execute arbitrary code with SYTEM privileges. |
Risk And Classification
Problem Types: CWE-428
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Siemens | Simatic Automatic Tool | All | All | All | All |
| Application | Siemens | Simatic Automatic Tool | All | All | All | All |
| Application | Siemens | Simatic Net Pc | All | All | All | All |
| Application | Siemens | Simatic Net Pc | 16 | - | All | All |
| Application | Siemens | Simatic Net Pc | 16 | update1 | All | All |
| Application | Siemens | Simatic Net Pc | All | All | All | All |
| Application | Siemens | Simatic Net Pc | 16 | - | All | All |
| Application | Siemens | Simatic Net Pc | 16 | update1 | All | All |
| Application | Siemens | Simatic Pcs 7 | All | All | All | All |
| Application | Siemens | Simatic Pcs 7 | All | All | All | All |
| Application | Siemens | Simatic Pcs Neo | All | All | All | All |
| Application | Siemens | Simatic Pcs Neo | All | All | All | All |
| Application | Siemens | Simatic Prosave | All | All | All | All |
| Application | Siemens | Simatic Prosave | All | All | All | All |
| Hardware | Siemens | Simatic S7-150 | - | All | All | All |
| Hardware | Siemens | Simatic S7-150 | - | All | All | All |
| Application | Siemens | Simatic S7-1500 Software Controller | All | All | All | All |
| Operating System | Siemens | Simatic S7-150 Firmware | All | All | All | All |
| Operating System | Siemens | Simatic S7-150 Firmware | All | All | All | All |
| Application | Siemens | Simatic Step 7 | All | All | All | All |
| Application | Siemens | Simatic Step 7 | 5.6 | - | All | All |
| Application | Siemens | Simatic Step 7 | 5.6 | sp1 | All | All |
| Application | Siemens | Simatic Step 7 | 5.6 | sp2 | All | All |
| Application | Siemens | Simatic Step 7 | 5.6 | sp2_hotfix1 | All | All |
| Application | Siemens | Simatic Step 7 | All | All | All | All |
| Application | Siemens | Simatic Step 7 | 5.6 | - | All | All |
| Application | Siemens | Simatic Step 7 | 5.6 | sp1 | All | All |
| Application | Siemens | Simatic Step 7 | 5.6 | sp2 | All | All |
| Application | Siemens | Simatic Step 7 | 5.6 | sp2_hotfix1 | All | All |
| Application | Siemens | Simatic Step 7 | All | All | All | All |
| Application | Siemens | Simatic Wincc | All | All | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | - | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update1 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update10 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update11 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update12 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update13 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update2 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update3 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update4 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update5 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update6 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update7 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update8 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update9 | All | All |
| Application | Siemens | Simatic Wincc | 7.5 | - | All | All |
| Application | Siemens | Simatic Wincc | 7.5 | sp1 | All | All |
| Application | Siemens | Simatic Wincc | 7.5 | sp1_update1 | All | All |
| Application | Siemens | Simatic Wincc | 7.5 | sp1_update2 | All | All |
| Application | Siemens | Simatic Wincc | All | All | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | - | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update1 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update10 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update11 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update12 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update13 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update2 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update3 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update4 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update5 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update6 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update7 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update8 | All | All |
| Application | Siemens | Simatic Wincc | 7.4 | sp1_update9 | All | All |
| Application | Siemens | Simatic Wincc | 7.5 | - | All | All |
| Application | Siemens | Simatic Wincc | 7.5 | sp1 | All | All |
| Application | Siemens | Simatic Wincc | 7.5 | sp1_update1 | All | All |
| Application | Siemens | Simatic Wincc | 7.5 | sp1_update2 | All | All |
| Application | Siemens | Simatic Wincc Open Architecture | 3.16 | All | All | All |
| Application | Siemens | Simatic Wincc Open Architecture | 3.17 | All | All | All |
| Application | Siemens | Simatic Wincc Open Architecture | 3.16 | All | All | All |
| Application | Siemens | Simatic Wincc Open Architecture | 3.17 | All | All | All |
| Application | Siemens | Simatic Wincc Runtime Advanced | All | All | All | All |
| Application | Siemens | Simatic Wincc Runtime Advanced | All | All | All | All |
| Application | Siemens | Simatic Wincc Runtime Professional | All | All | All | All |
| Application | Siemens | Sinamics Startdrive | All | All | All | All |
| Application | Siemens | Sinamics Startdrive | All | All | All | All |
| Application | Siemens | Sinamics Starter Commissioning Tool | All | All | All | All |
| Application | Siemens | Sinamics Starter Commissioning Tool | All | All | All | All |
| Application | Siemens | Sinec Network Management System | All | All | All | All |
| Application | Siemens | Sinec Network Management System | All | All | All | All |
| Application | Siemens | Sinema Server | All | All | All | All |
| Application | Siemens | Sinema Server | All | All | All | All |
| Application | Siemens | Sinumerik One Virtual | All | All | All | All |
| Application | Siemens | Sinumerik One Virtual | All | All | All | All |
| Application | Siemens | Sinumerik Operate | All | All | All | All |
| Application | Siemens | Sinumerik Operate | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| cert-portal.siemens.com/productcert/pdf/ssa-312271.pdf | MISC | cert-portal.siemens.com | Vendor Advisory |
| Siemens SIMATIC, SINAMICS, SINEC, SINEMA, SINUMERIK (Update B) | CISA | MISC | us-cert.cisa.gov | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 590592 Siemens SIMATIC, SINAMICS, SINEC, SINEMA, SINUMERIK (Update I) Unquoted Search Path or Element Vulnerability (ICSA-20-161-04)
- 591007 Siemens SIMATIC NMS and SINAMICS Stardrive (Update J) Multiple Vulnerabilities (ICSA-20-161-04)
- 591164 Siemens SIMATIC NET PC Software Unquoted Search Path Vulnerability (SSA-312271)