CVE-2020-10048 Information
Jun 07, 2022
cve
Description
A vulnerability has been identified in SIMATIC PCS 7 (All versions) SIMATIC WinCC (All versions < V7.5 SP2). Due to an insecure password verification process an attacker could bypass the password protection set on protected files thus being granted access to the protected content circumventing authentication.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Reference
https://cert-portal.siemens.com/productcert/pdf/ssa-944678.pdf
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
5.5
Share on: