This could allow an unauthenticated remote attacker to create files in writable directories outside the intended location and thus compromise integrity of files in those writable directories.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-42528 | A vulnerability has been identified in Siemens SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate a file path that is supplied to an endpoint intended to create CSR files. This could allow an unauthenticated remote attacker to create files in writable directories outside the intended location and thus compromise integrity of files in those writable directories. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 08 Oct 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Siemens
Siemens sinec Security Monitor |
|
| CPEs | cpe:2.3:a:siemens:sinec_security_monitor:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Siemens
Siemens sinec Security Monitor |
|
| Metrics |
ssvc
|
Tue, 08 Oct 2024 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified in Siemens SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate a file path that is supplied to an endpoint intended to create CSR files. This could allow an unauthenticated remote attacker to create files in writable directories outside the intended location and thus compromise integrity of files in those writable directories. | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: siemens
Published:
Updated: 2024-10-08T16:28:09.708Z
Reserved: 2024-09-27T10:57:37.067Z
Link: CVE-2024-47563
Updated: 2024-10-08T16:28:04.060Z
Status : Analyzed
Published: 2024-10-08T09:15:18.403
Modified: 2024-10-11T20:05:05.143
Link: CVE-2024-47563
No data.
OpenCVE Enrichment
No data.
EUVD