Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-7586


A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3), SIMATIC PDM (All versions < V9.2), SIMATIC STEP 7 V5.X (All versions < V5.6 SP2 HF3), SINAMICS STARTER (containing STEP 7 OEM version) (All versions < V5.4 HF2). A buffer overflow vulnerability could allow a local attacker to cause a Denial-of-Service situation. The security vulnerability could be exploited by an attacker with local access to the affected systems. Successful exploitation requires user privileges but no user interaction. The vulnerability could allow an attacker to compromise the availability of the system as well as to have access to confidential information.


Published

2020-06-10T17:15:12.520

Last Modified

2024-11-21T05:37:25.427

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.9

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-122
  • Type: Secondary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application siemens simatic_pcs_7 * Yes
Application siemens simatic_process_device_manager * Yes
Application siemens simatic_step_7 < 5.6 Yes
Application siemens simatic_step_7 5.6 Yes
Application siemens simatic_step_7 5.6 Yes
Application siemens simatic_step_7 5.6 Yes
Application siemens simatic_step_7 5.6 Yes
Application siemens sinamics_starter < 5.4 Yes
Application siemens sinamics_starter 5.4 Yes

References