CVE-2020-10048: Medium severity siemens simatic pcs 7 telecontrol firmware vulnerability
A vulnerability has been identified in SIMATIC PCS 7 (All versions), SIMATIC WinCC (All versions < V7.5 SP2). Due to an insecure password verification process, an attacker could bypass the password protection set on protected files, thus being granted access to the protected content, circumventing authentication.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-10048?
The severity of CVE-2020-10048 is medium with a score of 5.5.
Which software versions are affected by CVE-2020-10048?
SIMATIC PCS 7 (All versions) and SIMATIC WinCC (All versions < V7.5 SP2) are affected by CVE-2020-10048.
How does the vulnerability in CVE-2020-10048 allow the bypass of password protection?
The vulnerability in CVE-2020-10048 allows an attacker to bypass the password protection on protected files through an insecure password verification process.
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2020-10048.
Are there any fixes available for CVE-2020-10048?
Refer to the Siemens Security Advisory SSA-944678 for available fixes and mitigation steps for CVE-2020-10048.