A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1). Affected applications improperly assign permissions to critical directories and files used by the application processes. This could allow a local unprivileged attacker to achieve code execution with ADMINISTRATOR or even NT AUTHORITY/SYSTEM privileges.
2022-04-12T09:15:14.233
2024-11-21T06:48:34.530
Modified
CVSSv3.1: 7.8 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | siemens | simatic_energy_manager_basic | < 7.3 | Yes |
Application | siemens | simatic_energy_manager_basic | 7.3 | Yes |
Application | siemens | simatic_energy_manager_pro | < 7.3 | Yes |
Application | siemens | simatic_energy_manager_pro | 7.3 | Yes |