CVE detail
CVE-2020-28390 — CVE-2020-28390
Published 2021-01-12 · Modified 2026-06-17 · Vendor siemens · Product opcenter_execution_core · Source nvd
MEDIUM
severity
CVSS-derived band
0.0044
EPSS probability
exploitation probability, 30d
36.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A vulnerability has been identified in Opcenter Execution Core (V8.2), Opcenter Execution Core (V8.3). The application contains an information leakage vulnerability in the handling of web client sessions. A local attacker who has access to the Web Client Session Storage could disclose the passwords of currently logged-in users.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References