CVE-2020-7586: Buffer Overflow
A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3), SIMATIC PDM (All versions < V9.2), SIMATIC STEP 7 V5.X (All versions < V5.6 SP2 HF3), SINAMICS STARTER (containing STEP 7 OEM version) (All versions < V5.4 HF2). A buffer overflow vulnerability could allow a local attacker to cause a Denial-of-Service situation. The security vulnerability could be exploited by an attacker with local access to the affected systems. Successful exploitation requires user privileges but no user interaction. The vulnerability could allow an attacker to compromise the availability of the system as well as to have access to confidential information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-7586?
The severity of CVE-2020-7586 is rated as high.
Which software versions are affected by CVE-2020-7586?
SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3), SIMATIC PDM (All versions < V9.2), SIMATIC STEP 7 V5.X (All versions < V5.6 SP2 HF3), SINAMICS STARTER (containing STEP 7 OEM version) (All versions < V5.4 HF2).
How can I fix CVE-2020-7586?
Siemens has released security updates and recommends updating to the latest version of affected software.
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-7586?
The CWE IDs for CVE-2020-7586 are 119, 122, and 787.
Where can I find more information about CVE-2020-7586?
You can find more information about CVE-2020-7586 in the following references: [Siemens ProductCERT](https://cert-portal.siemens.com/productcert/pdf/ssa-689942.pdf), [US-CERT Advisory](https://us-cert.cisa.gov/ics/advisories/icsa-20-161-05), [US-CERT ICS Advisory](https://www.us-cert.gov/ics/advisories/icsa-20-161-05).