PT-2022-3584 · Siemens · Simatic Energy Manager Pro+1

Published

2022-01-19

·

Updated

2022-04-19

·

CVE-2022-23448

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SIMATIC Energy Manager Basic versions prior to V7.3 Update 1 SIMATIC Energy Manager PRO versions prior to V7.3 Update 1
Description The issue is related to the improper assignment of permissions to critical directories and files used by the application processes. This could allow a local unprivileged attacker to achieve code execution with elevated privileges, such as ADMINISTRATOR or NT AUTHORITY/SYSTEM.
Recommendations For SIMATIC Energy Manager Basic versions prior to V7.3 Update 1, update to version V7.3 Update 1 or later. For SIMATIC Energy Manager PRO versions prior to V7.3 Update 1, update to version V7.3 Update 1 or later.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04368
BDU:2022-04690
CVE-2022-23448

Affected Products

Simatic Energy Manager Basic
Simatic Energy Manager Pro