CVE-2020-7580
Published on: 06/10/2020 12:00:00 AM UTC
Last Modified on: 12/13/2022 05:15:00 PM UTC
Certain versions of Simatic Automatic Tool from Siemens contain the following vulnerability:
A vulnerability has been identified in SIMATIC Automation Tool (All versions < V4 SP2), SIMATIC NET PC Software V14 (All versions < V14 SP1 Update 14), SIMATIC NET PC Software V15 (All versions), SIMATIC NET PC Software V16 (All versions < V16 Upd3), SIMATIC PCS neo (All versions < V3.0 SP1), SIMATIC ProSave (All versions < V17), SIMATIC S7-1500 Software Controller (All versions < V21.8), SIMATIC STEP 7 (TIA Portal) V13 (All versions < V13 SP2 Update 4), SIMATIC STEP 7 (TIA Portal) V14 (All versions < V14 SP1 Update 10), SIMATIC STEP 7 (TIA Portal) V15 (All versions < V15.1 Update 5), SIMATIC STEP 7 (TIA Portal) V16 (All versions < V16 Update 2), SIMATIC STEP 7 V5 (All versions < V5.6 SP2 HF3), SIMATIC WinCC OA V3.16 (All versions < V3.16 P018), SIMATIC WinCC OA V3.17 (All versions < V3.17 P003), SIMATIC WinCC Runtime Advanced (All versions < V16 Update 2), SIMATIC WinCC Runtime Professional V13 (All versions < V13 SP2 Update 4), SIMATIC WinCC Runtime Professional V14 (All versions < V14 SP1 Update 10), SIMATIC WinCC Runtime Professional V15 (All versions < V15.1 Update 5), SIMATIC WinCC Runtime Professional V16 (All versions < V16 Update 2), SIMATIC WinCC V7.4 (All versions < V7.4 SP1 Update 14), SIMATIC WinCC V7.5 (All versions < V7.5 SP1 Update 3), SINAMICS STARTER (All Versions < V5.4 HF2), SINAMICS Startdrive (All Versions < V16 Update 3), SINEC NMS (All versions < V1.0 SP2), SINEMA Server (All versions < V14 SP3), SINUMERIK ONE virtual (All Versions < V6.14), SINUMERIK Operate (All Versions < V6.14). A common component used by the affected applications regularly calls a helper binary with SYSTEM privileges while the call path is not quoted. This could allow a local attacker to execute arbitrary code with SYTEM privileges.
- CVE-2020-7580 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
CVSS3 Score: 6.7 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | HIGH | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 7.2 - HIGH
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
LOCAL | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
COMPLETE | COMPLETE | COMPLETE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Vendor Advisory cert-portal.siemens.com application/pdf |
![]() | |
Siemens SIMATIC, SINAMICS, SINEC, SINEMA, SINUMERIK (Update B) | CISA | Third Party Advisory US Government Resource us-cert.cisa.gov text/html |
![]() |
Related QID Numbers
- 590592 Siemens SIMATIC, SINAMICS, SINEC, SINEMA, SINUMERIK (Update I) Unquoted Search Path or Element Vulnerability (ICSA-20-161-04)
- 591007 Siemens SIMATIC NMS and SINAMICS Stardrive (Update J) Multiple Vulnerabilities (ICSA-20-161-04)
- 591164 Siemens SIMATIC NET PC Software Unquoted Search Path Vulnerability (SSA-312271)
Exploit/POC from Github
A vulnerability has been identified in SIMATIC Automation Tool (All versions < V4 SP2), SIMATIC NET PC Software V14 (…
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Siemens | Simatic Automatic Tool | All | All | All | All |
Application | Siemens | Simatic Automatic Tool | All | All | All | All |
Application | Siemens | Simatic Net Pc | All | All | All | All |
Application | Siemens | Simatic Net Pc | 16 | - | All | All |
Application | Siemens | Simatic Net Pc | 16 | update1 | All | All |
Application | Siemens | Simatic Net Pc | All | All | All | All |
Application | Siemens | Simatic Net Pc | 16 | - | All | All |
Application | Siemens | Simatic Net Pc | 16 | update1 | All | All |
Application | Siemens | Simatic Pcs 7 | All | All | All | All |
Application | Siemens | Simatic Pcs 7 | All | All | All | All |
Application | Siemens | Simatic Pcs Neo | All | All | All | All |
Application | Siemens | Simatic Pcs Neo | All | All | All | All |
Application | Siemens | Simatic Prosave | All | All | All | All |
Application | Siemens | Simatic Prosave | All | All | All | All |
Hardware
| Siemens | Simatic S7-150 | - | All | All | All |
Hardware
| Siemens | Simatic S7-150 | - | All | All | All |
Operating System | Siemens | Simatic S7-150 Firmware | All | All | All | All |
Operating System | Siemens | Simatic S7-150 Firmware | All | All | All | All |
Application | Siemens | Simatic Step 7 | All | All | All | All |
Application | Siemens | Simatic Step 7 | 5.6 | - | All | All |
Application | Siemens | Simatic Step 7 | 5.6 | sp1 | All | All |
Application | Siemens | Simatic Step 7 | 5.6 | sp2 | All | All |
Application | Siemens | Simatic Step 7 | 5.6 | sp2_hotfix1 | All | All |
Application | Siemens | Simatic Step 7 | All | All | All | All |
Application | Siemens | Simatic Step 7 | 5.6 | - | All | All |
Application | Siemens | Simatic Step 7 | 5.6 | sp1 | All | All |
Application | Siemens | Simatic Step 7 | 5.6 | sp2 | All | All |
Application | Siemens | Simatic Step 7 | 5.6 | sp2_hotfix1 | All | All |
Application | Siemens | Simatic Step 7 | All | All | All | All |
Application | Siemens | Simatic Wincc | All | All | All | All |
Application | Siemens | Simatic Wincc | 7.4 | - | All | All |
Application | Siemens | Simatic Wincc | 7.4 | sp1 | All | All |
Application | Siemens | Simatic Wincc | 7.4 | sp1_update1 | All | All |
Application | Siemens | Simatic Wincc | 7.4 | sp1_update10 | All | All |
Application | Siemens | Simatic Wincc | 7.4 | sp1_update11 | All | All |
Application | Siemens | Simatic Wincc | 7.4 | sp1_update12 | All | All |
Application | Siemens | Simatic Wincc | 7.4 | sp1_update13 | All | All |
Application | Siemens | Simatic Wincc | 7.4 | sp1_update2 | All | All |
Application | Siemens | Simatic Wincc | 7.4 | sp1_update3 | All | All |
Application | Siemens | Simatic Wincc | 7.4 | sp1_update4 | All | All |
Application | Siemens | Simatic Wincc | 7.4 | sp1_update5 | All | All |
Application | Siemens | Simatic Wincc | 7.4 | sp1_update6 | All | All |
Application | Siemens | Simatic Wincc | 7.4 | sp1_update7 | All | All |
Application | Siemens | Simatic Wincc | 7.4 | sp1_update8 | All | All |
Application | Siemens | Simatic Wincc | 7.4 | sp1_update9 | All | All |
Application | Siemens | Simatic Wincc | 7.5 | - | All | All |
Application | Siemens | Simatic Wincc | 7.5 | sp1 | All | All |
Application | Siemens | Simatic Wincc | 7.5 | sp1_update1 | All | All |
Application | Siemens | Simatic Wincc | 7.5 | sp1_update2 | All | All |
Application | Siemens | Simatic Wincc | All | All | All | All |
Application | Siemens | Simatic Wincc | 7.4 | - | All | All |
Application | Siemens | Simatic Wincc | 7.4 | sp1 | All | All |
Application | Siemens | Simatic Wincc | 7.4 | sp1_update1 | All | All |
Application | Siemens | Simatic Wincc | 7.4 | sp1_update10 | All | All |
Application | Siemens | Simatic Wincc | 7.4 | sp1_update11 | All | All |
Application | Siemens | Simatic Wincc | 7.4 | sp1_update12 | All | All |
Application | Siemens | Simatic Wincc | 7.4 | sp1_update13 | All | All |
Application | Siemens | Simatic Wincc | 7.4 | sp1_update2 | All | All |
Application | Siemens | Simatic Wincc | 7.4 | sp1_update3 | All | All |
Application | Siemens | Simatic Wincc | 7.4 | sp1_update4 | All | All |
Application | Siemens | Simatic Wincc | 7.4 | sp1_update5 | All | All |
Application | Siemens | Simatic Wincc | 7.4 | sp1_update6 | All | All |
Application | Siemens | Simatic Wincc | 7.4 | sp1_update7 | All | All |
Application | Siemens | Simatic Wincc | 7.4 | sp1_update8 | All | All |
Application | Siemens | Simatic Wincc | 7.4 | sp1_update9 | All | All |
Application | Siemens | Simatic Wincc | 7.5 | - | All | All |
Application | Siemens | Simatic Wincc | 7.5 | sp1 | All | All |
Application | Siemens | Simatic Wincc | 7.5 | sp1_update1 | All | All |
Application | Siemens | Simatic Wincc | 7.5 | sp1_update2 | All | All |
Application | Siemens | Simatic Wincc Open Architecture | 3.16 | All | All | All |
Application | Siemens | Simatic Wincc Open Architecture | 3.17 | All | All | All |
Application | Siemens | Simatic Wincc Open Architecture | 3.16 | All | All | All |
Application | Siemens | Simatic Wincc Open Architecture | 3.17 | All | All | All |
Application | Siemens | Simatic Wincc Runtime Advanced | All | All | All | All |
Application | Siemens | Simatic Wincc Runtime Advanced | All | All | All | All |
Application | Siemens | Simatic Wincc Runtime Professional | All | All | All | All |
Application | Siemens | Sinamics Startdrive | All | All | All | All |
Application | Siemens | Sinamics Startdrive | All | All | All | All |
Application | Siemens | Sinamics Starter Commissioning Tool | All | All | All | All |
Application | Siemens | Sinamics Starter Commissioning Tool | All | All | All | All |
Application | Siemens | Sinec Network Management System | All | All | All | All |
Application | Siemens | Sinec Network Management System | All | All | All | All |
Application | Siemens | Sinema Server | All | All | All | All |
Application | Siemens | Sinema Server | All | All | All | All |
Application | Siemens | Sinumerik One Virtual | All | All | All | All |
Application | Siemens | Sinumerik One Virtual | All | All | All | All |
Application | Siemens | Sinumerik Operate | All | All | All | All |
Application | Siemens | Sinumerik Operate | All | All | All | All |
- cpe:2.3:a:siemens:simatic_automatic_tool:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_automatic_tool:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_net_pc:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_net_pc:16:-:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_net_pc:16:update1:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_net_pc:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_net_pc:16:-:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_net_pc:16:update1:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_pcs_7:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_pcs_7:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_pcs_neo:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_pcs_neo:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_prosave:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_prosave:*:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:simatic_s7-150:-:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:simatic_s7-150:-:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:simatic_s7-150_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:simatic_s7-150_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_step_7:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_step_7:5.6:-:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_step_7:5.6:sp1:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_step_7:5.6:sp2:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_step_7:5.6:sp2_hotfix1:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_step_7:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_step_7:5.6:-:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_step_7:5.6:sp1:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_step_7:5.6:sp2:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_step_7:5.6:sp2_hotfix1:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_step_7:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.4:-:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.4:sp1:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update1:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update10:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update11:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update12:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update13:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update2:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update3:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update4:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update5:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update6:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update7:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update8:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update9:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.5:-:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.5:sp1:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.5:sp1_update1:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.5:sp1_update2:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.4:-:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.4:sp1:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update1:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update10:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update11:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update12:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update13:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update2:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update3:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update4:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update5:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update6:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update7:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update8:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update9:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.5:-:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.5:sp1:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.5:sp1_update1:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc:7.5:sp1_update2:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc_open_architecture:3.16:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc_open_architecture:3.17:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc_open_architecture:3.16:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc_open_architecture:3.17:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc_runtime_advanced:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc_runtime_advanced:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simatic_wincc_runtime_professional:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:sinamics_startdrive:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:sinamics_startdrive:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:sinamics_starter_commissioning_tool:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:sinamics_starter_commissioning_tool:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:sinec_network_management_system:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:sinec_network_management_system:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:sinema_server:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:sinema_server:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:sinumerik_one_virtual:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:sinumerik_one_virtual:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:sinumerik_operate:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:sinumerik_operate:*:*:*:*:*:*:*:*:
Social Mentions
Source | Title | Posted (UTC) |
---|