High severity7.8NVD Advisory· Published Feb 9, 2021· Updated Jun 17, 2026
CVE-2020-25238
CVE-2020-25238
Description
A vulnerability has been identified in PCS neo (Administration Console) (All versions < V3.1), TIA Portal (V15, V15.1 and V16). Manipulating certain files in specific folders could allow a local attacker to execute code with SYSTEM privileges. The security vulnerability could be exploited by an attacker with a valid account and limited access rights on the system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8- Range: <V3.1
- Range: V15, V15.1 and V16
- Range: V15, V15.1 and V16
- cpe:2.3:a:siemens:simatic_process_control_system_neo:*:*:*:*:*:*:*:*Range: <3.1
cpe:2.3:a:siemens:totally_integrated_automation_portal:15:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:siemens:totally_integrated_automation_portal:15:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:totally_integrated_automation_portal:15.1:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:totally_integrated_automation_portal:16:*:*:*:*:*:*:*
- Siemens/PCS neo (Administration Console)v5Range: All versions < V3.1
Patches
Vulnerability mechanics
References
3- cert-portal.siemens.com/productcert/pdf/ssa-428051.pdfnvdVendor Advisory
- us-cert.cisa.gov/ics/advisories/icsa-21-040-05nvdThird Party AdvisoryUS Government ResourceVDB Entry
- www.kb.cert.org/vuls/id/466044nvdThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.