CVE-2020-10048

A vulnerability has been identified in SIMATIC PCS 7 (All versions), SIMATIC WinCC (All versions < V7.5 SP2). Due to an insecure password verification process, an attacker could bypass the password protection set on protected files, thus being granted access to the protected content, circumventing authentication.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:siemens:simatic_pcs_7:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:simatic_wincc:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:simatic_wincc:7.5:sp1:*:*:*:*:*:*
cpe:2.3:a:siemens:simatic_wincc:7.5:sp1_update1:*:*:*:*:*:*
cpe:2.3:a:siemens:simatic_wincc:7.5:sp1_update2:*:*:*:*:*:*

Information

Published : 2021-02-09 09:15

Updated : 2021-02-10 19:37


NVD link : CVE-2020-10048

Mitre link : CVE-2020-10048


JSON object : View

CWE
CWE-287

Improper Authentication

Advertisement

dedicated server usa

Products Affected

siemens

  • simatic_pcs_7
  • simatic_wincc