CVE-2020-28392: Siemens Simaris Configuration

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability has been identified in SIMARIS configuration (All versions < V4.0.1). During installation to default target folder, incorrect permissions are configured for the application folder and subfolders which could allow an attacker to gain persistence or potentially escalate privileges should a user with elevated credentials log onto the machine.

Affected products

  • Siemens Simaris Configuration: before 4.0.1 (fixed in 4.0.1)

Published 2021-02-09. Last modified 2026-06-17.