CVE-2020-10055
Severity CVSS v4.0:
Pending analysis
Type:
CWE-94
Code Injection
Publication date:
14/08/2020
Last modified:
21/08/2020
Description
A vulnerability has been identified in Desigo CC (V4.x), Desigo CC (V3.x), Desigo CC Compact (V4.x), Desigo CC Compact (V3.x). Affected applications are delivered with a 3rd party component (BIRT) that contains a remote code execution vulnerability if the Advanced Reporting Engine is enabled. The vulnerability could allow a remote unauthenticated attacker to execute arbitrary commands on the server with SYSTEM privileges.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
9.30
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:siemens:desigo_consumption_control:3.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:siemens:desigo_consumption_control:4.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:siemens:desigo_consumption_control_compact:3.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:siemens:desigo_consumption_control_compact:4.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page