PT-2023-1971 · Siemens · Tia Multiuser Server+1

Published

2023-02-14

·

Updated

2024-08-13

·

CVE-2022-35868

CVSS v3.1

6.7

Medium

VectorAV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TIA Multiuser Server versions prior to V15.1 Update 8 TIA Project-Server versions prior to V1.1 TIA Project-Server V16 (All versions) TIA Project-Server V17 versions prior to V17 Update 6
Description The issue is related to an untrusted search path vulnerability. This could allow an attacker to escalate privileges by tricking a legitimate user into starting the service from an attacker-controlled path. The vulnerability is associated with the use of an untrusted search path in the software.
Recommendations For TIA Multiuser Server versions prior to V15.1 Update 8, update to V15.1 Update 8 or later. For TIA Project-Server versions prior to V1.1, update to V1.1 or later. For TIA Project-Server V16, consider disabling the service until a patch is available. For TIA Project-Server V17 versions prior to V17 Update 6, update to V17 Update 6 or later.

Fix

Untrusted Search Path

Weakness Enumeration

Related Identifiers

BDU:2023-01585
CVE-2022-35868

Affected Products

Tia Multiuser Server
Tia Project-Server