Publication Date: |
2020-12-08 |
Last Update: |
2020-12-08 |
Current Version: |
V1.0 |
CVSS v3.1 Base Score: |
9.8 |
- Apply Defense-in-Depth concept, including protection concept outlined in the system manual.
CVSS v3.1 Base Score |
9.8 |
CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-306: Missing Authentication for Critical Function |
CVSS v3.1 Base Score |
8.1 |
CVSS Vector |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C |
CWE: |
CWE-321: Use of Hard-coded Cryptographic Key |
CVSS v3.1 Base Score |
5.9 |
CVSS Vector |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C |
CWE: |
CWE-327: Use of a Broken or Risky Cryptographic Algorithm |
CVSS v3.1 Base Score |
6.2 |
CVSS Vector |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C |
CWE: |
CWE-321: Use of Hard-coded Cryptographic Key |
CVSS v3.1 Base Score |
5.9 |
CVSS Vector |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C |
CWE: |
CWE-327: Use of a Broken or Risky Cryptographic Algorithm |
CVSS v3.1 Base Score |
6.2 |
CVSS Vector |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C |
CWE: |
CWE-321: Use of Hard-coded Cryptographic Key |
CVSS v3.1 Base Score |
7.7 |
CVSS Vector |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:P/RL:O/RC:C |
CWE: |
CWE-321: Use of Hard-coded Cryptographic Key |
CVSS v3.1 Base Score |
5.9 |
CVSS Vector |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C |
CWE: |
CWE-522: Insufficiently Protected Credentials |
-
Tobias Gebhardt
for coordinated disclosure of CVE-2020-25228
-
Thomas Meesters from
cirosec GmbH
for coordinated disclosure of CVE-2020-25229 to CVE-2020-25234
-
Max Bäumler
for coordinated disclosure of CVE-2020-25235
https://www.siemens.com/cert/advisories