« Volver al listado

CVE-2020-10056

Estado: ModificadaAlta (7.8)—

Se ha identificado una vulnerabilidad en License Management Utility (LMU) (todas las versiones anteriores a V2.4). El servicio lmgrd de la aplicación afectada se ejecuta con privilegios SYSTEM local en el servidor, mientras que los usuarios locales pueden modificar su configuración. La vulnerabilidad podría permitir a un atacante local autenticado ejecutar comandos arbitrarios en el servidor con privilegios SYSTEM local.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-10056",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.2,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "productcert@siemens.com",
      "affectedData": [
        {
          "vendor": "Siemens AG",
          "product": "License Management Utility (LMU)",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V2.4"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-09-09T19:15:18.773",
  "references": [
    {
      "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-709003.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "productcert@siemens.com"
    },
    {
      "url": "https://us-cert.cisa.gov/ics/advisories/icsa-20-252-03",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "productcert@siemens.com"
    },
    {
      "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-709003.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://us-cert.cisa.gov/ics/advisories/icsa-20-252-03",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "productcert@siemens.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-250"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-269"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability has been identified in License Management Utility (LMU) (All versions < V2.4). The lmgrd service of the affected application is executed with local SYSTEM privileges on the server while its configuration can be modified by local users. The vulnerability could allow a local authenticated attacker to execute arbitrary commands on the server with local SYSTEM privileges."
    },
    {
      "lang": "es",
      "value": "Se ha identificado una vulnerabilidad en License Management Utility (LMU) (todas las versiones anteriores a V2.4).&#xa0;El servicio lmgrd de la aplicación afectada se ejecuta con privilegios SYSTEM local en el servidor, mientras que los usuarios locales pueden modificar su configuración.&#xa0;La vulnerabilidad podría permitir a un atacante local autenticado ejecutar comandos arbitrarios en el servidor con privilegios SYSTEM local."
    }
  ],
  "lastModified": "2026-06-17T02:47:16.093",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:siemens:license_management_utility:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "692C154C-1574-4388-9A3A-DA0532E018A6",
              "versionEndExcluding": "2.4"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "productcert@siemens.com"
}