PT-2022-3584 · Siemens · Simatic Energy Manager Pro+1
Published
2022-01-19
·
Updated
2022-04-19
·
CVE-2022-23448
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SIMATIC Energy Manager Basic versions prior to V7.3 Update 1
SIMATIC Energy Manager PRO versions prior to V7.3 Update 1
Description
The issue is related to the improper assignment of permissions to critical directories and files used by the application processes. This could allow a local unprivileged attacker to achieve code execution with elevated privileges, such as ADMINISTRATOR or NT AUTHORITY/SYSTEM.
Recommendations
For SIMATIC Energy Manager Basic versions prior to V7.3 Update 1, update to version V7.3 Update 1 or later.
For SIMATIC Energy Manager PRO versions prior to V7.3 Update 1, update to version V7.3 Update 1 or later.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simatic Energy Manager Basic
Simatic Energy Manager Pro