Publication Date: 2020-08-11
Last Update: 2020-08-11
Current Version: V1.0
CVSS v3.1 Base Score: 9.8

Affected Product and Versions Remediation
Desigo CC:
V4.x
Apply the patch provided through Siemens online support:
https://support.industry.siemens.com/cs/ww/en/view/109780860 (Login required)
Desigo CC:
V3.x
Apply the patch provided through Siemens online support:
https://support.industry.siemens.com/cs/ww/en/view/109780956 (Login required)
Desigo CC Compact:
V4.x
Apply the patch provided through Siemens online support:
https://support.industry.siemens.com/cs/ww/en/view/109780860 (Login required)
Desigo CC Compact:
V3.x
Apply the patch provided through Siemens online support:
https://support.industry.siemens.com/cs/ww/en/view/109780956 (Login required)

CVSS v3.1 Base Score 9.8
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
CWE: CWE-94: Improper Control of Generation of Code (‘Code Injection’)

https://www.siemens.com/cert/advisories