Lucene search

K
cvelistSiemensCVELIST:CVE-2020-10055
HistoryAug 14, 2020 - 3:24 p.m.

CVE-2020-10055

2020-08-1415:24:06
CWE-94
siemens
www.cve.org

9.9 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

76.0%

A vulnerability has been identified in Desigo CC (V4.x), Desigo CC (V3.x), Desigo CC Compact (V4.x), Desigo CC Compact (V3.x). Affected applications are delivered with a 3rd party component (BIRT) that contains a remote code execution vulnerability if the Advanced Reporting Engine is enabled. The vulnerability could allow a remote unauthenticated attacker to execute arbitrary commands on the server with SYSTEM privileges.

CNA Affected

[
  {
    "product": "Desigo CC",
    "vendor": "Siemens AG",
    "versions": [
      {
        "status": "affected",
        "version": "V4.x"
      }
    ]
  },
  {
    "product": "Desigo CC",
    "vendor": "Siemens AG",
    "versions": [
      {
        "status": "affected",
        "version": "V3.x"
      }
    ]
  },
  {
    "product": "Desigo CC Compact",
    "vendor": "Siemens AG",
    "versions": [
      {
        "status": "affected",
        "version": "V4.x"
      }
    ]
  },
  {
    "product": "Desigo CC Compact",
    "vendor": "Siemens AG",
    "versions": [
      {
        "status": "affected",
        "version": "V3.x"
      }
    ]
  }
]

9.9 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

76.0%

Related for CVELIST:CVE-2020-10055