A vulnerability has been identified in SIMATIC Automation Tool (All versions < V4 SP2), SIMATIC NET PC Software V14 (All versions < V14 SP1 Update 14), SIMATIC NET PC Software V15 (All versions), SIMATIC NET PC Software V16 (All versions < V16 Upd3), SIMATIC PCS neo (All versions < V3.0 SP1), SIMATIC ProSave (All versions < V17), SIMATIC S7-1500 Software Controller (All versions < V21.8), SIMATIC STEP 7 (TIA Portal) V13 (All versions < V13 SP2 Update 4), SIMATIC STEP 7 (TIA Portal) V14 (All versions < V14 SP1 Update 10), SIMATIC STEP 7 (TIA Portal) V15 (All versions < V15.1 Update 5), SIMATIC STEP 7 (TIA Portal) V16 (All versions < V16 Update 2), SIMATIC STEP 7 V5 (All versions < V5.6 SP2 HF3), SIMATIC WinCC OA V3.16 (All versions < V3.16 P018), SIMATIC WinCC OA V3.17 (All versions < V3.17 P003), SIMATIC WinCC Runtime Advanced (All versions < V16 Update 2), SIMATIC WinCC Runtime Professional V13 (All versions < V13 SP2 Update 4), SIMATIC WinCC Runtime Professional V14 (All versions < V14 SP1 Update 10), SIMATIC WinCC Runtime Professional V15 (All versions < V15.1 Update 5), SIMATIC WinCC Runtime Professional V16 (All versions < V16 Update 2), SIMATIC WinCC V7.4 (All versions < V7.4 SP1 Update 14), SIMATIC WinCC V7.5 (All versions < V7.5 SP1 Update 3), SINAMICS STARTER (All Versions < V5.4 HF2), SINAMICS Startdrive (All Versions < V16 Update 3), SINEC NMS (All versions < V1.0 SP2), SINEMA Server (All versions < V14 SP3), SINUMERIK ONE virtual (All Versions < V6.14), SINUMERIK Operate (All Versions < V6.14). A common component used by the affected applications regularly calls a helper binary with SYSTEM privileges while the call path is not quoted. This could allow a local attacker to execute arbitrary code with SYTEM privileges.
Conclusion & alert: CVE-2020-7580 is rated Low Risk (39.4/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.44%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.05% | 0.44% | +0.39% |
| 2 | 2025-04-20 | 0.14% | 0.05% | -0.09% |
| 3 | 2025-04-18 | — | 0.14% | — |
Full EPSS history (12 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.7 | 3.1 | MEDIUM |
|
0.8 | 5.9 | [email protected] |
| 7.2 | 2.0 | HIGH |
|
3.9 | 10.0 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| siemens | simatic_automatic_tool | — | cpe:2.3:a:siemens:simatic_automatic_tool:*:*:*:*:*:*:*:* |
| siemens | simatic_net_pc | < 16 | cpe:2.3:a:siemens:simatic_net_pc:*:*:*:*:*:*:*:* |
| siemens | simatic_net_pc | 16 | cpe:2.3:a:siemens:simatic_net_pc:16:-:*:*:*:*:*:* |
| siemens | simatic_net_pc | 16 | cpe:2.3:a:siemens:simatic_net_pc:16:update1:*:*:*:*:*:* |
| siemens | simatic_pcs_7 | — | cpe:2.3:a:siemens:simatic_pcs_7:*:*:*:*:*:*:*:* |
| siemens | simatic_pcs_neo | — | cpe:2.3:a:siemens:simatic_pcs_neo:*:*:*:*:*:*:*:* |
| siemens | simatic_prosave | — | cpe:2.3:a:siemens:simatic_prosave:*:*:*:*:*:*:*:* |
| siemens | simatic_s7-1500_software_controller | < 21.8 | cpe:2.3:a:siemens:simatic_s7-1500_software_controller:*:*:*:*:*:*:*:* |
| siemens | simatic_step_7 | < 5.6 | cpe:2.3:a:siemens:simatic_step_7:*:*:*:*:*:*:*:* |
| siemens | simatic_step_7 | >= 13, <= 16 | cpe:2.3:a:siemens:simatic_step_7:*:*:*:*:*:*:*:* |
| siemens | simatic_step_7 | 5.6 | cpe:2.3:a:siemens:simatic_step_7:5.6:-:*:*:*:*:*:* |
| siemens | simatic_step_7 | 5.6 | cpe:2.3:a:siemens:simatic_step_7:5.6:sp1:*:*:*:*:*:* |
| siemens | simatic_step_7 | 5.6 | cpe:2.3:a:siemens:simatic_step_7:5.6:sp2:*:*:*:*:*:* |
| siemens | simatic_step_7 | 5.6 | cpe:2.3:a:siemens:simatic_step_7:5.6:sp2_hotfix1:*:*:*:*:*:* |
| siemens | simatic_wincc | < 7.4 | cpe:2.3:a:siemens:simatic_wincc:*:*:*:*:*:*:*:* |
| siemens | simatic_wincc | 7.4 | cpe:2.3:a:siemens:simatic_wincc:7.4:-:*:*:*:*:*:* |
| siemens | simatic_wincc | 7.4 | cpe:2.3:a:siemens:simatic_wincc:7.4:sp1:*:*:*:*:*:* |
| siemens | simatic_wincc | 7.4 | cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update1:*:*:*:*:*:* |
| siemens | simatic_wincc | 7.4 | cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update10:*:*:*:*:*:* |
| siemens | simatic_wincc | 7.4 | cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update11:*:*:*:*:*:* |
| siemens | simatic_wincc | 7.4 | cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update12:*:*:*:*:*:* |
| siemens | simatic_wincc | 7.4 | cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update13:*:*:*:*:*:* |
| siemens | simatic_wincc | 7.4 | cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update2:*:*:*:*:*:* |
| siemens | simatic_wincc | 7.4 | cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update3:*:*:*:*:*:* |
| siemens | simatic_wincc | 7.4 | cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update4:*:*:*:*:*:* |
| siemens | simatic_wincc | 7.4 | cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update5:*:*:*:*:*:* |
| siemens | simatic_wincc | 7.4 | cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update6:*:*:*:*:*:* |
| siemens | simatic_wincc | 7.4 | cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update7:*:*:*:*:*:* |
| siemens | simatic_wincc | 7.4 | cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update8:*:*:*:*:*:* |
| siemens | simatic_wincc | 7.4 | cpe:2.3:a:siemens:simatic_wincc:7.4:sp1_update9:*:*:*:*:*:* |
| siemens | simatic_wincc | 7.5 | cpe:2.3:a:siemens:simatic_wincc:7.5:-:*:*:*:*:*:* |
| siemens | simatic_wincc | 7.5 | cpe:2.3:a:siemens:simatic_wincc:7.5:sp1:*:*:*:*:*:* |
| siemens | simatic_wincc | 7.5 | cpe:2.3:a:siemens:simatic_wincc:7.5:sp1_update1:*:*:*:*:*:* |
| siemens | simatic_wincc | 7.5 | cpe:2.3:a:siemens:simatic_wincc:7.5:sp1_update2:*:*:*:*:*:* |
| siemens | simatic_wincc_open_architecture | 3.16 | cpe:2.3:a:siemens:simatic_wincc_open_architecture:3.16:*:*:*:*:*:*:* |
| siemens | simatic_wincc_open_architecture | 3.17 | cpe:2.3:a:siemens:simatic_wincc_open_architecture:3.17:*:*:*:*:*:*:* |
| siemens | simatic_wincc_runtime_advanced | — | cpe:2.3:a:siemens:simatic_wincc_runtime_advanced:*:*:*:*:*:*:*:* |
| siemens | simatic_wincc_runtime_professional | >= 13, <= 16 | cpe:2.3:a:siemens:simatic_wincc_runtime_professional:*:*:*:*:*:*:*:* |
| siemens | sinamics_startdrive | — | cpe:2.3:a:siemens:sinamics_startdrive:*:*:*:*:*:*:*:* |
| siemens | sinamics_starter_commissioning_tool | — | cpe:2.3:a:siemens:sinamics_starter_commissioning_tool:*:*:*:*:*:*:*:* |
| siemens | sinec_network_management_system | — | cpe:2.3:a:siemens:sinec_network_management_system:*:*:*:*:*:*:*:* |
| siemens | sinema_server | — | cpe:2.3:a:siemens:sinema_server:*:*:*:*:*:*:*:* |
| siemens | sinumerik_one_virtual | — | cpe:2.3:a:siemens:sinumerik_one_virtual:*:*:*:*:*:*:*:* |
| siemens | sinumerik_operate | — | cpe:2.3:a:siemens:sinumerik_operate:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://cert-portal.siemens.com/productcert/pdf/ssa-312271.pdf | Vendor Advisory |
| https://us-cert.cisa.gov/ics/advisories/icsa-20-161-04 | Third Party Advisory US Government Resource |