Show plain JSON{"id": "CVE-2020-7593", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 7.5, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 6.4, "baseSeverity": "HIGH", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 9.8, "attackVector": "NETWORK", "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 3.9}]}, "published": "2020-07-14T14:15:19.150", "references": [{"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-573753.pdf", "tags": ["Vendor Advisory"], "source": "productcert@siemens.com"}, {"url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1069", "tags": ["Exploit", "Third Party Advisory"], "source": "productcert@siemens.com"}], "vulnStatus": "Analyzed", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-120"}]}, {"type": "Secondary", "source": "productcert@siemens.com", "description": [{"lang": "en", "value": "CWE-120"}]}], "descriptions": [{"lang": "en", "value": "A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (V1.81.01 - V1.81.03), LOGO! 8 BM (incl. SIPLUS variants) (V1.82.01), LOGO! 8 BM (incl. SIPLUS variants) (V1.82.02). A buffer overflow vulnerability exists in the Web Server functionality of the device. A remote unauthenticated attacker could send a specially crafted HTTP request to cause a memory corruption, potentially resulting in remote code execution."}, {"lang": "es", "value": "Se ha identificado una vulnerabilidad en LOGO! 8 BM (incluyendo las variantes SIPLUS) (versiones V1.81.01 - V1.81.03), LOGO! 8 BM (incluyendo las variantes SIPLUS) (versi\u00f3n V1.82.01), LOGO! 8 BM (incluyendo las variantes SIPLUS) (versi\u00f3n V1.82.02). Se presenta una vulnerabilidad de desbordamiento del b\u00fafer en la funcionalidad Web Server del dispositivo. Un atacante remoto no autenticado podr\u00eda enviar una petici\u00f3n HTTP especialmente dise\u00f1ada para causar da\u00f1os en la memoria, resultando potencialmente en una ejecuci\u00f3n de c\u00f3digo remota"}], "lastModified": "2020-07-22T13:54:23.993", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:siemens:logo\\!_8_bm_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1008F18E-ADAE-4E5E-96E1-1516560A6D07", "versionEndIncluding": "1.81.03", "versionStartIncluding": "1.81.01"}, {"criteria": "cpe:2.3:o:siemens:logo\\!_8_bm_firmware:1.82.01:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6E096EF1-CCBA-4F81-BEED-963E43A60DB0"}, {"criteria": "cpe:2.3:o:siemens:logo\\!_8_bm_firmware:1.82.02:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F87E0DFC-2333-4AFB-8CF9-E34A73E3521E"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:siemens:logo\\!_8_bm:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "59947FF6-3711-47C1-B91E-87DBF31DAF57"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "productcert@siemens.com"}