Vulnerability Details CVE-2020-25238
A vulnerability has been identified in PCS neo (Administration Console) (All versions < V3.1), TIA Portal (V15, V15.1 and V16). Manipulating certain files in specific folders could allow a local attacker to execute code with SYSTEM privileges. The security vulnerability could be exploited by an attacker with a valid account and limited access rights on the system.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 31.5%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 7.2
Products affected by CVE-2020-25238
-
cpe:2.3:a:siemens:simatic_process_control_system_neo:3.0
-
cpe:2.3:a:siemens:totally_integrated_automation_portal:15
-
cpe:2.3:a:siemens:totally_integrated_automation_portal:15.1
-
cpe:2.3:a:siemens:totally_integrated_automation_portal:16