A vulnerability has been identified in Siemens SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate user input to the ```ssmctl-client``` command.
This could allow an authenticated, lowly privileged remote attacker to execute arbitrary code with root privileges on the underlying OS.
This could allow an authenticated, lowly privileged remote attacker to execute arbitrary code with root privileges on the underlying OS.
Metrics
Affected Vendors & Products
References
History
Tue, 08 Oct 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Siemens
Siemens sinec Security Monitor |
|
CPEs | cpe:2.3:a:siemens:sinec_security_monitor:*:*:*:*:*:*:*:* | |
Vendors & Products |
Siemens
Siemens sinec Security Monitor |
|
Metrics |
ssvc
|
Tue, 08 Oct 2024 09:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability has been identified in Siemens SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate user input to the ```ssmctl-client``` command. This could allow an authenticated, lowly privileged remote attacker to execute arbitrary code with root privileges on the underlying OS. | |
Weaknesses | CWE-88 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: siemens
Published:
Updated: 2024-10-08T16:37:31.430Z
Reserved: 2024-09-26T13:01:20.792Z
Link: CVE-2024-47553

Updated: 2024-10-08T16:37:27.349Z

Status : Analyzed
Published: 2024-10-08T09:15:17.847
Modified: 2024-10-11T20:04:08.623
Link: CVE-2024-47553

No data.

No data.