CVE-2020-28392: Siemens Simaris Configuration
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
A vulnerability has been identified in SIMARIS configuration (All versions < V4.0.1). During installation to default target folder, incorrect permissions are configured for the application folder and subfolders which could allow an attacker to gain persistence or potentially escalate privileges should a user with elevated credentials log onto the machine.
Affected products
- Siemens Simaris Configuration: before 4.0.1 (fixed in 4.0.1)
Published 2021-02-09. Last modified 2026-06-17.