A vulnerability has been identified in Desigo CC (V4.x), Desigo CC (V3.x), Desigo CC Compact (V4.x), Desigo CC Compact (V3.x). Affected applications are delivered with a 3rd party component (BIRT) that contains a remote code execution vulnerability if the Advanced Reporting Engine is enabled. The vulnerability could allow a remote unauthenticated attacker to execute arbitrary commands on the server with SYSTEM privileges.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2024-08-04T10:50:57.784Z

Reserved: 2020-03-04T00:00:00

Link: CVE-2020-10055

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-08-14T16:15:16.790

Modified: 2024-11-21T04:54:42.960

Link: CVE-2020-10055

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.