ID

VAR-202009-0054


CVE

CVE-2020-10056


TITLE

License Management Utility  Vulnerability in privilege management

Trust: 0.8

sources: JVNDB: JVNDB-2020-010868

DESCRIPTION

A vulnerability has been identified in License Management Utility (LMU) (All versions < V2.4). The lmgrd service of the affected application is executed with local SYSTEM privileges on the server while its configuration can be modified by local users. The vulnerability could allow a local authenticated attacker to execute arbitrary commands on the server with local SYSTEM privileges. License Management Utility (LMU) Contains a privilege management vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state

Trust: 2.25

sources: NVD: CVE-2020-10056 // JVNDB: JVNDB-2020-010868 // CNVD: CNVD-2020-51235 // VULMON: CVE-2020-10056

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-51235

AFFECTED PRODUCTS

vendor:siemensmodel:license management utilityscope:ltversion:2.4

Trust: 1.6

vendor:シーメンスmodel:license management utilityscope:eqversion:2.4

Trust: 0.8

vendor:シーメンスmodel:license management utilityscope:eqversion: -

Trust: 0.8

sources: CNVD: CNVD-2020-51235 // JVNDB: JVNDB-2020-010868 // NVD: CVE-2020-10056

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-10056
value: HIGH

Trust: 1.0

NVD: CVE-2020-10056
value: HIGH

Trust: 0.8

CNVD: CNVD-2020-51235
value: HIGH

Trust: 0.6

CNNVD: CNNVD-202009-507
value: HIGH

Trust: 0.6

VULMON: CVE-2020-10056
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2020-10056
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

CNVD: CNVD-2020-51235
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2020-10056
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2020-10056
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2020-51235 // VULMON: CVE-2020-10056 // JVNDB: JVNDB-2020-010868 // CNNVD: CNNVD-202009-507 // NVD: CVE-2020-10056

PROBLEMTYPE DATA

problemtype:CWE-269

Trust: 1.0

problemtype:CWE-250

Trust: 1.0

problemtype:Improper authority management (CWE-269) [NVD Evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2020-010868 // NVD: CVE-2020-10056

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202009-507

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202009-507

PATCH

title:SSA-709003url:https://cert-portal.siemens.com/productcert/pdf/ssa-709003.pdf

Trust: 0.8

title:Patch for Siemens License Management Utility (LMU) Privilege Escalation Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/233365

Trust: 0.6

title:Siemens LMU Repair measures for privilege escalation vulnerabilityurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=127926

Trust: 0.6

title:Siemens Security Advisories: Siemens Security Advisoryurl:https://vulmon.com/vendoradvisory?qidtp=siemens_security_advisories&qid=4adf45b5d2a57468213b8e815721aa36

Trust: 0.1

title: - url:https://github.com/Live-Hack-CVE/CVE-2020-10056

Trust: 0.1

sources: CNVD: CNVD-2020-51235 // VULMON: CVE-2020-10056 // JVNDB: JVNDB-2020-010868 // CNNVD: CNNVD-202009-507

EXTERNAL IDS

db:NVDid:CVE-2020-10056

Trust: 3.9

db:ICS CERTid:ICSA-20-252-03

Trust: 2.5

db:SIEMENSid:SSA-709003

Trust: 2.3

db:JVNid:JVNVU94568336

Trust: 0.8

db:JVNDBid:JVNDB-2020-010868

Trust: 0.8

db:CNVDid:CNVD-2020-51235

Trust: 0.6

db:AUSCERTid:ESB-2020.3093

Trust: 0.6

db:CNNVDid:CNNVD-202009-507

Trust: 0.6

db:VULMONid:CVE-2020-10056

Trust: 0.1

sources: CNVD: CNVD-2020-51235 // VULMON: CVE-2020-10056 // JVNDB: JVNDB-2020-010868 // CNNVD: CNNVD-202009-507 // NVD: CVE-2020-10056

REFERENCES

url:https://us-cert.cisa.gov/ics/advisories/icsa-20-252-03

Trust: 2.5

url:https://cert-portal.siemens.com/productcert/pdf/ssa-709003.pdf

Trust: 2.3

url:https://nvd.nist.gov/vuln/detail/cve-2020-10056

Trust: 1.4

url:https://jvn.jp/vu/jvnvu94568336/

Trust: 0.8

url:https://www.auscert.org.au/bulletins/esb-2020.3093/

Trust: 0.6

url:https://cwe.mitre.org/data/definitions/250.html

Trust: 0.1

url:https://github.com/live-hack-cve/cve-2020-10056

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://cert-portal.siemens.com/productcert/txt/ssa-709003.txt

Trust: 0.1

sources: CNVD: CNVD-2020-51235 // VULMON: CVE-2020-10056 // JVNDB: JVNDB-2020-010868 // CNNVD: CNNVD-202009-507 // NVD: CVE-2020-10056

SOURCES

db:CNVDid:CNVD-2020-51235
db:VULMONid:CVE-2020-10056
db:JVNDBid:JVNDB-2020-010868
db:CNNVDid:CNNVD-202009-507
db:NVDid:CVE-2020-10056

LAST UPDATE DATE

2024-11-23T19:27:08.717000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-51235date:2020-09-10T00:00:00
db:VULMONid:CVE-2020-10056date:2023-01-24T00:00:00
db:JVNDBid:JVNDB-2020-010868date:2022-03-11T06:10:00
db:CNNVDid:CNNVD-202009-507date:2023-01-28T00:00:00
db:NVDid:CVE-2020-10056date:2024-11-21T04:54:43.070

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-51235date:2020-09-10T00:00:00
db:VULMONid:CVE-2020-10056date:2020-09-09T00:00:00
db:JVNDBid:JVNDB-2020-010868date:2021-02-12T00:00:00
db:CNNVDid:CNNVD-202009-507date:2020-09-08T00:00:00
db:NVDid:CVE-2020-10056date:2020-09-09T19:15:18.773