Protection Mechanism Failure in Siemens products - CVE-2020-28396

 

Protection Mechanism Failure in Siemens products - CVE-2020-28396

Published: December 9, 2020


Vulnerability identifier: #VU48892
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-28396
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to insufficient implementation of security measures. An attacker can bypass implemented security restrictions and elevate privileges on the system.


Affected software

SICAM A8000 CP-8000
SICAM A8000 CP-8021
SICAM A8000 CP-8022

How to mitigate CVE-2020-28396

Install updates from vendor's website.

SICAM A8000 CP-8000 - update to 16
SICAM A8000 CP-8021 - update to 16
SICAM A8000 CP-8022 - update to 16

External References

Related Security Bulletins