A vulnerability has been identified in Siemens SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate a file path that is supplied to an endpoint intended to create CSR files.
This could allow an unauthenticated remote attacker to create files in writable directories outside the intended location and thus compromise integrity of files in those writable directories.
Metrics
Affected Vendors & Products
References
History
Tue, 08 Oct 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Siemens
Siemens sinec Security Monitor |
|
CPEs | cpe:2.3:a:siemens:sinec_security_monitor:*:*:*:*:*:*:*:* | |
Vendors & Products |
Siemens
Siemens sinec Security Monitor |
|
Metrics |
ssvc
|
Tue, 08 Oct 2024 09:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability has been identified in Siemens SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate a file path that is supplied to an endpoint intended to create CSR files. This could allow an unauthenticated remote attacker to create files in writable directories outside the intended location and thus compromise integrity of files in those writable directories. | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: siemens
Published: 2024-10-08T08:40:52.852Z
Updated: 2024-10-08T16:28:09.708Z
Reserved: 2024-09-27T10:57:37.067Z
Link: CVE-2024-47563
Vulnrichment
Updated: 2024-10-08T16:28:04.060Z
NVD
Status : Analyzed
Published: 2024-10-08T09:15:18.403
Modified: 2024-10-11T20:05:05.143
Link: CVE-2024-47563
Redhat
No data.