CVE-2020-7580

Summary

CVECVE-2020-7580
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2020-06-10 17:15:00 UTC
Updated2023-04-28 17:06:00 UTC
DescriptionA vulnerability has been identified in SIMATIC Automation Tool (All versions < V4 SP2), SIMATIC NET PC Software V14 (All versions < V14 SP1 Update 14), SIMATIC NET PC Software V15 (All versions), SIMATIC NET PC Software V16 (All versions < V16 Upd3), SIMATIC PCS neo (All versions < V3.0 SP1), SIMATIC ProSave (All versions < V17), SIMATIC S7-1500 Software Controller (All versions < V21.8), SIMATIC STEP 7 (TIA Portal) V13 (All versions < V13 SP2 Update 4), SIMATIC STEP 7 (TIA Portal) V14 (All versions < V14 SP1 Update 10), SIMATIC STEP 7 (TIA Portal) V15 (All versions < V15.1 Update 5), SIMATIC STEP 7 (TIA Portal) V16 (All versions < V16 Update 2), SIMATIC STEP 7 V5 (All versions < V5.6 SP2 HF3), SIMATIC WinCC OA V3.16 (All versions < V3.16 P018), SIMATIC WinCC OA V3.17 (All versions < V3.17 P003), SIMATIC WinCC Runtime Advanced (All versions < V16 Update 2), SIMATIC WinCC Runtime Professional V13 (All versions < V13 SP2 Update 4), SIMATIC WinCC Runtime Professional V14 (All versions < V14 SP1 Update 10), SIMATIC WinCC Runtime Professional V15 (All versions < V15.1 Update 5), SIMATIC WinCC Runtime Professional V16 (All versions < V16 Update 2), SIMATIC WinCC V7.4 (All versions < V7.4 SP1 Update 14), SIMATIC WinCC V7.5 (All versions < V7.5 SP1 Update 3), SINAMICS STARTER (All Versions < V5.4 HF2), SINAMICS Startdrive (All Versions < V16 Update 3), SINEC NMS (All versions < V1.0 SP2), SINEMA Server (All versions < V14 SP3), SINUMERIK ONE virtual (All Versions < V6.14), SINUMERIK Operate (All Versions < V6.14). A common component used by the affected applications regularly calls a helper binary with SYSTEM privileges while the call path is not quoted. This could allow a local attacker to execute arbitrary code with SYTEM privileges.

Risk And Classification

Problem Types: CWE-428

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Application Siemens Simatic Automatic Tool All All All All
Application Siemens Simatic Automatic Tool All All All All
Application Siemens Simatic Net Pc All All All All
Application Siemens Simatic Net Pc 16 - All All
Application Siemens Simatic Net Pc 16 update1 All All
Application Siemens Simatic Net Pc All All All All
Application Siemens Simatic Net Pc 16 - All All
Application Siemens Simatic Net Pc 16 update1 All All
Application Siemens Simatic Pcs 7 All All All All
Application Siemens Simatic Pcs 7 All All All All
Application Siemens Simatic Pcs Neo All All All All
Application Siemens Simatic Pcs Neo All All All All
Application Siemens Simatic Prosave All All All All
Application Siemens Simatic Prosave All All All All
Hardware Siemens Simatic S7-150 - All All All
Hardware Siemens Simatic S7-150 - All All All
Application Siemens Simatic S7-1500 Software Controller All All All All
Operating System Siemens Simatic S7-150 Firmware All All All All
Operating System Siemens Simatic S7-150 Firmware All All All All
Application Siemens Simatic Step 7 All All All All
Application Siemens Simatic Step 7 5.6 - All All
Application Siemens Simatic Step 7 5.6 sp1 All All
Application Siemens Simatic Step 7 5.6 sp2 All All
Application Siemens Simatic Step 7 5.6 sp2_hotfix1 All All
Application Siemens Simatic Step 7 All All All All
Application Siemens Simatic Step 7 5.6 - All All
Application Siemens Simatic Step 7 5.6 sp1 All All
Application Siemens Simatic Step 7 5.6 sp2 All All
Application Siemens Simatic Step 7 5.6 sp2_hotfix1 All All
Application Siemens Simatic Step 7 All All All All
Application Siemens Simatic Wincc All All All All
Application Siemens Simatic Wincc 7.4 - All All
Application Siemens Simatic Wincc 7.4 sp1 All All
Application Siemens Simatic Wincc 7.4 sp1_update1 All All
Application Siemens Simatic Wincc 7.4 sp1_update10 All All
Application Siemens Simatic Wincc 7.4 sp1_update11 All All
Application Siemens Simatic Wincc 7.4 sp1_update12 All All
Application Siemens Simatic Wincc 7.4 sp1_update13 All All
Application Siemens Simatic Wincc 7.4 sp1_update2 All All
Application Siemens Simatic Wincc 7.4 sp1_update3 All All
Application Siemens Simatic Wincc 7.4 sp1_update4 All All
Application Siemens Simatic Wincc 7.4 sp1_update5 All All
Application Siemens Simatic Wincc 7.4 sp1_update6 All All
Application Siemens Simatic Wincc 7.4 sp1_update7 All All
Application Siemens Simatic Wincc 7.4 sp1_update8 All All
Application Siemens Simatic Wincc 7.4 sp1_update9 All All
Application Siemens Simatic Wincc 7.5 - All All
Application Siemens Simatic Wincc 7.5 sp1 All All
Application Siemens Simatic Wincc 7.5 sp1_update1 All All
Application Siemens Simatic Wincc 7.5 sp1_update2 All All
Application Siemens Simatic Wincc All All All All
Application Siemens Simatic Wincc 7.4 - All All
Application Siemens Simatic Wincc 7.4 sp1 All All
Application Siemens Simatic Wincc 7.4 sp1_update1 All All
Application Siemens Simatic Wincc 7.4 sp1_update10 All All
Application Siemens Simatic Wincc 7.4 sp1_update11 All All
Application Siemens Simatic Wincc 7.4 sp1_update12 All All
Application Siemens Simatic Wincc 7.4 sp1_update13 All All
Application Siemens Simatic Wincc 7.4 sp1_update2 All All
Application Siemens Simatic Wincc 7.4 sp1_update3 All All
Application Siemens Simatic Wincc 7.4 sp1_update4 All All
Application Siemens Simatic Wincc 7.4 sp1_update5 All All
Application Siemens Simatic Wincc 7.4 sp1_update6 All All
Application Siemens Simatic Wincc 7.4 sp1_update7 All All
Application Siemens Simatic Wincc 7.4 sp1_update8 All All
Application Siemens Simatic Wincc 7.4 sp1_update9 All All
Application Siemens Simatic Wincc 7.5 - All All
Application Siemens Simatic Wincc 7.5 sp1 All All
Application Siemens Simatic Wincc 7.5 sp1_update1 All All
Application Siemens Simatic Wincc 7.5 sp1_update2 All All
Application Siemens Simatic Wincc Open Architecture 3.16 All All All
Application Siemens Simatic Wincc Open Architecture 3.17 All All All
Application Siemens Simatic Wincc Open Architecture 3.16 All All All
Application Siemens Simatic Wincc Open Architecture 3.17 All All All
Application Siemens Simatic Wincc Runtime Advanced All All All All
Application Siemens Simatic Wincc Runtime Advanced All All All All
Application Siemens Simatic Wincc Runtime Professional All All All All
Application Siemens Sinamics Startdrive All All All All
Application Siemens Sinamics Startdrive All All All All
Application Siemens Sinamics Starter Commissioning Tool All All All All
Application Siemens Sinamics Starter Commissioning Tool All All All All
Application Siemens Sinec Network Management System All All All All
Application Siemens Sinec Network Management System All All All All
Application Siemens Sinema Server All All All All
Application Siemens Sinema Server All All All All
Application Siemens Sinumerik One Virtual All All All All
Application Siemens Sinumerik One Virtual All All All All
Application Siemens Sinumerik Operate All All All All
Application Siemens Sinumerik Operate All All All All

References

ReferenceSourceLinkTags
cert-portal.siemens.com/productcert/pdf/ssa-312271.pdf MISC cert-portal.siemens.com Vendor Advisory
Siemens SIMATIC, SINAMICS, SINEC, SINEMA, SINUMERIK (Update B) | CISA MISC us-cert.cisa.gov Third Party Advisory, US Government Resource
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Legacy QID Mappings

  • 590592 Siemens SIMATIC, SINAMICS, SINEC, SINEMA, SINUMERIK (Update I) Unquoted Search Path or Element Vulnerability (ICSA-20-161-04)
  • 591007 Siemens SIMATIC NMS and SINAMICS Stardrive (Update J) Multiple Vulnerabilities (ICSA-20-161-04)
  • 591164 Siemens SIMATIC NET PC Software Unquoted Search Path Vulnerability (SSA-312271)
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report