CVE-2020-10048
published 2021-02-09CVE-2020-10048: A vulnerability has been identified in SIMATIC PCS 7 (All versions), SIMATIC WinCC (All versions < V7.5 SP2). Due to an insecure password verification process…
PriorityP429medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.34%
25.8th percentile
A vulnerability has been identified in SIMATIC PCS 7 (All versions), SIMATIC WinCC (All versions < V7.5 SP2). Due to an insecure password verification process, an attacker could bypass the password protection set on protected files, thus being granted access to the protected content, circumventing authentication.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | simatic_pcs_7 | — | — |
| siemens | simatic_wincc | < 7.5 | 7.5 |
| siemens | simatic_wincc | — | — |
| siemens | simatic_wincc | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
SIMATIC WinCC Graphics Designer
cisa_ics·2021-02-09·CVSS 5.5
[MEDIUM] SIMATIC WinCC Graphics Designer
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
SIMATIC WinCC Graphics Designer
Last RevisedFebruary 09, 2021
Alert CodeICSA-21-040-09
## 1. EXECUTIVE SUMMARY
- CVSS v3 6.2
- ATTENTION: Low skill level to exploit
- Vendor: Siemens
- Equipment: SIMATIC WinCC and PCS 7
- Vulnerability: Authentication Bypass Using an Alternate Path or Channel
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker unauthenticated access to protected files.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Siemens reports this vulnerability affects WinCC Graphics Designer used with the following DCS and
GHSA
GHSA-vmjg-j3qq-h4fv: A vulnerability has been identified in SIMATIC PCS 7 (All versions), SIMATIC WinCC (All versions < V7
ghsa_unreviewed·2022-05-24
CVE-2020-10048 [MEDIUM] CWE-287 GHSA-vmjg-j3qq-h4fv: A vulnerability has been identified in SIMATIC PCS 7 (All versions), SIMATIC WinCC (All versions < V7
A vulnerability has been identified in SIMATIC PCS 7 (All versions), SIMATIC WinCC (All versions < V7.5 SP2). Due to an insecure password verification process, an attacker could bypass the password protection set on protected files, thus being granted access to the protected content, circumventing authentication.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-02-09
Published