First published: Fri Aug 14 2020(Updated: )
A vulnerability has been identified in Desigo CC (V4.x), Desigo CC (V3.x), Desigo CC Compact (V4.x), Desigo CC Compact (V3.x). Affected applications are delivered with a 3rd party component (BIRT) that contains a remote code execution vulnerability if the Advanced Reporting Engine is enabled. The vulnerability could allow a remote unauthenticated attacker to execute arbitrary commands on the server with SYSTEM privileges.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Desigo Consumption Control | =3.0 | |
Siemens Desigo Consumption Control | =4.0 | |
Siemens Desigo Consumption Control Compact | =3.0 | |
Siemens Desigo Consumption Control Compact | =4.0 | |
Siemens Desigo CC | ||
Siemens Desigo CC |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10055 has a high severity rating due to the potential for remote code execution.
To fix CVE-2020-10055, disable the Advanced Reporting Engine if it is enabled in the affected Desigo CC or Desigo CC Compact applications.
CVE-2020-10055 affects Siemens Desigo CC and Desigo CC Compact versions 3.x and 4.x.
The impact of CVE-2020-10055 includes the risk of an attacker executing arbitrary code remotely on the affected systems.
There have been no specific reports of active exploitation for CVE-2020-10055, but the vulnerability poses a significant risk.