CVE-2020-25228
CRITICALSiemens LOGO! 8 BM Firmware <8.3 - Unauthenticated Remote Code Execution via Port 10005
Title source: llmDescription
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). A service available on port 10005/tcp of the affected devices could allow complete access to all services without authorization. An attacker could gain full control over an affected device, if he has access to this service. The system manual recommends to protect access to this port.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_misc
https://cert-portal.siemens.com/productcert/pdf/ssa-480824.pdf
Scores
CVSS v3
9.8
EPSS
0.0044
EPSS Percentile
63.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-306
Status
published
Products (1)
siemens/logo\!_8_bm_firmware
< 8.3
Published
Dec 14, 2020
Tracked Since
Feb 18, 2026