PT-2021-11118 · Siemens · Tia Portal+1

Will Dormann

·

Published

2021-02-09

·

Updated

2022-10-21

·

CVE-2020-25238

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: PCS neo (Administration Console) versions prior to V3.1 TIA Portal versions V15 through V16
Description: A vulnerability has been identified that could allow a local attacker to execute code with SYSTEM privileges by manipulating certain files in specific folders. The issue can be exploited by an attacker with a valid account and limited access rights on the system.
Recommendations: For PCS neo (Administration Console) versions prior to V3.1, update to version V3.1 or later to resolve the issue. For TIA Portal versions V15 through V16, update to a version later than V16 to resolve the issue. As a temporary workaround, consider restricting access to sensitive folders and files to minimize the risk of exploitation.

Fix

Improper Access Control

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

CVE-2020-25238

Affected Products

Pcs Neo
Tia Portal