Impact
A local privilege escalation vulnerability exists in Siemens License Server (SLS) versions older than V5.1. The flaw arises from an insecure sudoers policy that permits authenticated local users to execute commands with elevated privileges. An attacker who can gain local access to the system can run arbitrary commands as root and deploy malicious files, resulting in complete system compromise. This weakness is mapped to CWE‑732, which enumerates insecure or missing permissions for users.
Affected Systems
The vulnerability affects all Siemens License Server (SLS) deployments with versions earlier than V5.1. No specific vendor version penalty beyond the general < V5.1 threshold is noted.
Risk and Exploitability
The CVSS score of 8.3 classifies the flaw as high severity. Because the attack requires local access and relies on an insecure sudoers configuration, the likelihood of exploitation depends on the level of local user access, which may vary across environments. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, but the high CVSS value warrants immediate remediation.
OpenCVE Enrichment