CVE-2020-7585 PUBLISHED CVSS 7.800000190734863 HIGH

A vulnerability has been identified in SIMATIC PCS 7 (All versions), SIMATIC PDM (All versions), SIMATIC STEP 7 V5.X (All versions < V5.6 SP2 HF3), SINAMICS STARTER (containing STEP 7 OEM version) (All versions < V5.4 HF1). A DLL Hijacking vulnerability could allow a local attacker to execute code with elevated privileges. The security vulnerability could be exploited by an attacker with local access to the affected systems. Successful exploitation requires user privileges but no user interaction. The vulnerability could allow an attacker to compromise the availability of the system as well as to have access to confidential information.

EPSS 0.09% · 25.0th percentile

Risk Scores

CVSS v3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.09%
25.0th percentile

Affected Products

VendorProductVersions
siemenssimatic_step_75.6, 5.6, 5.6
SiemensSINAMICS STARTER (containing STEP 7 OEM version)All versions < V5.4 HF2
siemenssimatic_process_device_manager
SiemensSIMATIC PCS 7 V8.2 and earlierAll versions
SiemensSIMATIC PCS 7 V9.0All versions < V9.0 SP3
SiemensSIMATIC PDMAll versions < V9.2
siemenssinamics_starter0, 5.4
siemenssimatic_pcs_7
SiemensSIMATIC STEP 7 V5.XAll versions < V5.6 SP2 HF3

Timeline

References

Open in Interactive Console →