PT-2023-1971 · Siemens · Tia Multiuser Server+1
CVE-2022-35868
·
Publicado
2023-02-14
·
Atualizado
2024-08-13
CVSS v3.1
6.7
Média
| Vetor | AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TIA Multiuser Server versions prior to V15.1 Update 8
TIA Project-Server versions prior to V1.1
TIA Project-Server V16 (All versions)
TIA Project-Server V17 versions prior to V17 Update 6
Description
The issue is related to an untrusted search path vulnerability. This could allow an attacker to escalate privileges by tricking a legitimate user into starting the service from an attacker-controlled path. The vulnerability is associated with the use of an untrusted search path in the software.
Recommendations
For TIA Multiuser Server versions prior to V15.1 Update 8, update to V15.1 Update 8 or later.
For TIA Project-Server versions prior to V1.1, update to V1.1 or later.
For TIA Project-Server V16, consider disabling the service until a patch is available.
For TIA Project-Server V17 versions prior to V17 Update 6, update to V17 Update 6 or later.
Correção
Untrusted Search Path
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Tia Multiuser Server
Tia Project-Server