CVE-2020-10055
A vulnerability has been identified in Desigo CC (V4.x), Desigo CC (V3.x), Desigo CC Compact (V4.x), Desigo CC Compact (V3.x).
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.98%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A vulnerability has been identified in Desigo CC (V4.x), Desigo CC (V3.x), Desigo CC Compact (V4.x), Desigo CC Compact (V3.x). Affected applications are delivered with a 3rd party component (BIRT) that contains a remote code execution vulnerability if the Advanced Reporting Engine is enabled. The vulnerability could allow a remote unauthenticated attacker to execute arbitrary commands on the server with SYSTEM privileges.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 5.98% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- siemens/desigo consumption control · siemens/desigo consumption control compact
- Source
- productcert@siemens.com
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-786743.pdfPatch, Vendor Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-20-224-06Patch, Third Party Advisory, US Government Resource
- https://cert-portal.siemens.com/productcert/pdf/ssa-786743.pdfPatch, Vendor Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-20-224-06Patch, Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.