CVE-2020-10048Authentication Bypass Using an Alternate Path or Channel in Siemens Simatic Wincc

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 82.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 9
Latest updateMay 24

Description

A vulnerability has been identified in SIMATIC PCS 7 (All versions), SIMATIC WinCC (All versions < V7.5 SP2). Due to an insecure password verification process, an attacker could bypass the password protection set on protected files, thus being granted access to the protected content, circumventing authentication.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

CVEListV5siemens/simatic_winccAll versions < V7.5 SP2
CVEListV5siemens/simatic_pcs_7All versions

🔴Vulnerability Details

2
GHSA
GHSA-vmjg-j3qq-h4fv: A vulnerability has been identified in SIMATIC PCS 7 (All versions), SIMATIC WinCC (All versions < V72022-05-24
CVEList
CVE-2020-10048: A vulnerability has been identified in SIMATIC PCS 7 (All versions), SIMATIC WinCC (All versions < V72021-02-09
CVE-2020-10048 — Siemens Simatic Wincc vulnerability | cvebase