Local Code Execution Vulnerability in Siemens Products
CVE-2020-7581
6.7MEDIUM
Key Information:
- Vendor
Siemens
- Status
- Vendor
- CVE Published:
- 14 July 2020
What is CVE-2020-7581?
A local code execution vulnerability exists in several Siemens products due to a component calling a helper binary with SYSTEM privileges during startup. The call path is not quoted, which may permit an attacker with administrative access to exploit this flaw, potentially allowing for unauthorized execution of code at SYSTEM level. This could lead to significant security risks, including unauthorized access and system manipulation.
Affected Version(s)
Opcenter Execution Discrete All versions < V3.2
Opcenter Execution Foundation All versions < V3.2
Opcenter Execution Process All versions < V3.2