Unquoted Search Path or Element in Siemens products - CVE-2020-7580
Published: June 10, 2020
Vulnerability details
The vulnerability allows a local user to execute arbitrary code on the target system.
The vulnerability exist due to a component within the affected application that regularly calls a helper binary with SYSTEM privileges while the call path is not quoted. A local administrator can execute arbitrary code with SYSTEM level privileges.
Affected software
Siemens SIMATIC WinCC
SINUMERIK ONE virtual
SIMATIC WinCC OA
SIMATIC STEP 7
SIMATIC S7-1500 Software Controller
SIMATIC PCS 7
SIMATIC NET PC Software
SIMATIC STEP 7 (TIA Portal)
SIMATIC WinCC Runtime Professional
SINEMA Server
SIMATIC Automation Tool
SINEC NMS
SINAMICS Startdrive
SIMATIC ProSave
SIMATIC PCS neo
How to mitigate CVE-2020-7580
SIMATIC WinCC OA - addressed in versions 3.16-P018, 3.17-P003
SIMATIC STEP 7 - update to 5.6 SP2 HF3
SIMATIC NET PC Software - update to 16 Upd3