PT-2021-11118 · Siemens · Tia Portal+1
Will Dormann
·
Published
2021-02-09
·
Updated
2022-10-21
·
CVE-2020-25238
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
PCS neo (Administration Console) versions prior to V3.1
TIA Portal versions V15 through V16
Description:
A vulnerability has been identified that could allow a local attacker to execute code with SYSTEM privileges by manipulating certain files in specific folders. The issue can be exploited by an attacker with a valid account and limited access rights on the system.
Recommendations:
For PCS neo (Administration Console) versions prior to V3.1, update to version V3.1 or later to resolve the issue.
For TIA Portal versions V15 through V16, update to a version later than V16 to resolve the issue.
As a temporary workaround, consider restricting access to sensitive folders and files to minimize the risk of exploitation.
Fix
Improper Access Control
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pcs Neo
Tia Portal