Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-45460


A vulnerability has been identified in SICAM PQ Analyzer (All versions < V3.18). A service is started by an unquoted registry entry. As there are spaces in this path, attackers with write privilege to those directories might be able to plant executables that will run in place of the legitimate process. Attackers might achieve persistence on the system ("backdoors") or cause a denial of service.


Published

2022-01-11T12:15:10.193

Last Modified

2024-11-21T06:32:15.223

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.1 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:N/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.0

Impact Score

4.9

Weaknesses
  • Type: Secondary
    CWE-428
  • Type: Primary
    CWE-428

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System siemens sicam_pq_analyzer_firmware < 3.18 Yes
Hardware siemens sicam_pq_analyzer - No

References