CVE-2020-7586 PUBLISHED CVSS 7.800000190734863 HIGH

A vulnerability has been identified in SIMATIC PCS 7 (All versions), SIMATIC PDM (All versions), SIMATIC STEP 7 V5.X (All versions < V5.6 SP2 HF3), SINAMICS STARTER (containing STEP 7 OEM version) (All versions < V5.4 HF1). A buffer overflow vulnerability could allow a local attacker to cause a Denial-of-Service situation. The security vulnerability could be exploited by an attacker with local access to the affected systems. Successful exploitation requires user privileges but no user interaction. The vulnerability could allow an attacker to compromise the availability of the system as well as to have access to confidential information.

EPSS 0.15% · 35.7th percentile

Risk Scores

CVSS v3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.15%
35.7th percentile

Affected Products

VendorProductVersions
siemenssimatic_pcs_7
SiemensSIMATIC STEP 7 V5.XAll versions < V5.6 SP2 HF3
siemenssimatic_process_device_manager
siemenssimatic_step_75.6, 5.6, 5.6
SiemensSIMATIC PDMAll versions < V9.2
siemenssinamics_starter5.4, 0
SiemensSIMATIC PCS 7 V8.2 and earlierAll versions
SiemensSIMATIC PCS 7 V9.0All versions < V9.0 SP3
SiemensSINAMICS STARTER (containing STEP 7 OEM version)All versions < V5.4 HF2

Timeline

References

Open in Interactive Console →