PT-2024-8131 · Siemens · Siemens Sinec Security Monitor

Published

2024-10-08

·

Updated

2024-10-11

·

CVE-2024-47563

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Siemens SINEC Security Monitor versions prior to V4.9.0
Description: A vulnerability has been identified in the application where it does not properly validate a file path supplied to an endpoint intended to create CSR files. This could allow an unauthenticated remote attacker to create files in writable directories outside the intended location, compromising the integrity of files in those writable directories. The issue is related to incorrect restriction of the directory path name with limited access, which may allow a remote attacker to create files in arbitrary directories.
Recommendations: For versions prior to V4.9.0, update to version V4.9.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the endpoint intended to create CSR files until a patch is available. Avoid using the vulnerable file path validation mechanism in the affected application until the issue is resolved.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-09670
CVE-2024-47563

Affected Products

Siemens Sinec Security Monitor