CVE-2020-25238

Description

A vulnerability has been identified in PCS neo (Administration Console) (All versions < V3.1), TIA Portal (V15, V15.1 and V16). Manipulating certain files in specific folders could allow a local attacker to execute code with SYSTEM privileges. The security vulnerability could be exploited by an attacker with a valid account and limited access rights on the system.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.116

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2019-10934,CVE-2020-25238,CVE-2022-27194,CVE-2023-30757 are affected in Siemens Totally Integrated Automation Portal (TIA Portal) 15.1Windows
Multiple Vulnerabilities are affected in Siemens Totally Integrated Automation Portal (TIA Portal) 16Windows
Multiple Vulnerabilities are affected in Siemens Totally Integrated Automation Portal (TIA Portal) 15Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234