PT-2021-11118 · Siemens · Tia Portal+1

·

CVE-2020-25238

·

Published

2021-02-09

·

Updated

2022-10-21

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: PCS neo (Administration Console) versions prior to V3.1 TIA Portal versions V15 through V16
Description: A vulnerability has been identified that could allow a local attacker to execute code with SYSTEM privileges by manipulating certain files in specific folders. The issue can be exploited by an attacker with a valid account and limited access rights on the system.
Recommendations: For PCS neo (Administration Console) versions prior to V3.1, update to version V3.1 or later to resolve the issue. For TIA Portal versions V15 through V16, update to a version later than V16 to resolve the issue. As a temporary workaround, consider restricting access to sensitive folders and files to minimize the risk of exploitation.

Fix

Improper Access Control

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-25238

Affected Products

Pcs Neo
Tia Portal