PT-2016-7504 · Siemens · Siemens Automation License Manager

Sergey Temnikov

+1

·

Published

2016-10-13

·

Updated

2017-07-29

·

CVE-2016-8565

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Siemens Automation License Manager (ALM) versions prior to 5.3 SP3
Description The issue allows remote attackers to perform unauthorized file system modifications, including writing to files, renaming files, creating directories, or deleting directories, by sending crafted packets.
Recommendations For versions prior to 5.3 SP3, update to version 5.3 SP3 or later to resolve the issue.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-8565

Affected Products

Siemens Automation License Manager