Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2020-7586 Details

Description

A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3), SIMATIC PDM (All versions < V9.2), SIMATIC STEP 7 V5.X (All versions < V5.6 SP2 HF3), SINAMICS STARTER (containing STEP 7 OEM version) (All versions < V5.4 HF2). A buffer overflow vulnerability could allow a local attacker to cause a Denial-of-Service situation. The security vulnerability could be exploited by an attacker with local access to the affected systems. Successful exploitation requires user privileges but no user interaction. The vulnerability could allow an attacker to compromise the availability of the system as well as to have access to confidential information.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-122Heap-based Buffer Overflow[email protected]
CWE-787Out-of-bounds Write[email protected]

Affected Products

ProductVersions
siemens simatic pcs 7
All versions

CPE

  • cpe:2.3:a:siemens:simatic_pcs_7:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
siemens simatic process device manager
All versions

CPE

  • cpe:2.3:a:siemens:simatic_process_device_manager:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
siemens simatic step 7
< 5.6
5.6 -
5.6 sp1
5.6 sp2
5.6 sp2_hotfix1

CPE

  • cpe:2.3:a:siemens:simatic_step_7:*:*:*:*:*:*:*:*
  • cpe:2.3:a:siemens:simatic_step_7:5.6:-:*:*:*:*:*:*
  • cpe:2.3:a:siemens:simatic_step_7:5.6:sp1:*:*:*:*:*:*
  • cpe:2.3:a:siemens:simatic_step_7:5.6:sp2:*:*:*:*:*:*
  • cpe:2.3:a:siemens:simatic_step_7:5.6:sp2_hotfix1:*:*:*:*:*:*

Remediation

  • No remediation found in references.
siemens sinamics starter
< 5.4
5.4 -

CPE

  • cpe:2.3:a:siemens:sinamics_starter:*:*:*:*:*:*:*:*
  • cpe:2.3:a:siemens:sinamics_starter:5.4:-:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

10 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2020-7586
NVD Published Date:
Jun 10, 2020
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2020-7586 Details - Not Deferred