CVE-2020-25238 PUBLISHED CVSS 7.800000190734863 HIGH

A vulnerability has been identified in PCS neo (Administration Console) (V3.0), TIA Portal (V15, V15.1 and V16). Manipulating certain files in specific folders could allow a local attacker to execute code with SYSTEM privileges. The security vulnerability could be exploited by an attacker with a valid account and limited access rights on the system.

EPSS 0.12% · 30.3th percentile

Risk Scores

CVSS v3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.12%
30.3th percentile

Affected Products

VendorProductVersions
SiemensTIA PortalV15, V15.1 and V16
siemenstotally_integrated_automation_portal15, 15.1, 16
siemenssimatic_process_control_system_neo0
SiemensPCS neo (Administration Console)All versions < V3.1

Timeline

References

Open in Interactive Console →