CVE-2020-7588: Input Validation
A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcenter Execution Process (All versions < V3.2), Opcenter Intelligence (All versions < V3.3), Opcenter Quality (All versions < V11.3), Opcenter RD&L (V8.0), SIMATIC IT LMS (All versions < V2.6), SIMATIC IT Production Suite (All versions < V8.0), SIMATIC Notifier Server for Windows (All versions), SIMATIC PCS neo (All versions < V3.0 SP1), SIMATIC STEP 7 (TIA Portal) V15 (All versions < V15.1 Update 5), SIMATIC STEP 7 (TIA Portal) V16 (All versions < V16 Update 2), SIMOCODE ES V15.1 (All versions < V15.1 Update 4), SIMOCODE ES V16 (All versions < V16 Update 1), Soft Starter ES V15.1 (All versions < V15.1 Update 3), Soft Starter ES V16 (All versions < V16 Update 1). Sending a specially crafted packet to the affected service could cause a partial remote denial-of-service, that would cause the service to restart itself.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-7588?
The severity of CVE-2020-7588 is medium with a severity value of 5.3.
Which software versions are affected by CVE-2020-7588?
Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcenter Execution Process (All versions < V3.2), Opcenter Intelligence (All versions < V3.3), Opcenter Quality (All versions < V11.3), Opcenter RD&L (V8.0), Siemens Simatic It Lms, Siemens Simatic It Production Suite, Siemens Simatic Notifier Server, Siemens Simatic Pcs Neo, Siemens SIMATIC STEP 7 (versions between 15 and 15.1, version 16 and version 16-update_1), Siemens Simocode Es, and Siemens Soft Starter Es are affected by CVE-2020-7588.
How can CVE-2020-7588 be fixed?
To fix CVE-2020-7588, it is recommended to update the affected software versions to V3.2 or higher for Opcenter Execution Discrete, Opcenter Execution Foundation, and Opcenter Execution Process. For Opcenter Intelligence, update to V3.3 or higher. For Opcenter Quality, update to V11.3 or higher. For Opcenter RD&L, update to the latest available version. Additionally, Siemens recommends implementing appropriate network security measures to protect against potential attacks.
What is the CWE of CVE-2020-7588?
The CWE of CVE-2020-7588 is CWE-20.
Where can I find more information about CVE-2020-7588?
More information about CVE-2020-7588 can be found in the following reference: [Siemens ProductCERT](https://cert-portal.siemens.com/productcert/pdf/ssa-841348.pdf).