CVE-2020-10055: Code Injection
A vulnerability has been identified in Desigo CC (V4.x), Desigo CC (V3.x), Desigo CC Compact (V4.x), Desigo CC Compact (V3.x). Affected applications are delivered with a 3rd party component (BIRT) that contains a remote code execution vulnerability if the Advanced Reporting Engine is enabled. The vulnerability could allow a remote unauthenticated attacker to execute arbitrary commands on the server with SYSTEM privileges.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-10055?
CVE-2020-10055 has a high severity rating due to the potential for remote code execution.
How do I fix CVE-2020-10055?
To fix CVE-2020-10055, disable the Advanced Reporting Engine if it is enabled in the affected Desigo CC or Desigo CC Compact applications.
Which versions are affected by CVE-2020-10055?
CVE-2020-10055 affects Siemens Desigo CC and Desigo CC Compact versions 3.x and 4.x.
What is the impact of CVE-2020-10055?
The impact of CVE-2020-10055 includes the risk of an attacker executing arbitrary code remotely on the affected systems.
Is CVE-2020-10055 being actively exploited?
There have been no specific reports of active exploitation for CVE-2020-10055, but the vulnerability poses a significant risk.