Impact
The vulnerability in Siemens License Server allows an attacker to specify a file path that is not properly sanitized, enabling a path traversal attack that can reveal arbitrary files hosted by the application. This flaw can lead to disclosure of sensitive configuration, authentication credentials, or other confidential data stored on the server.\n
Affected Systems
Siemens License Server (SLS) versions earlier than 5.3 are affected. All releases before V5.3 lack the necessary input sanitization to prevent path traversal.\n
Risk and Exploitability
With a CVSS score of 8.7, the vulnerability represents a high severity issue. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, but the potential for remote exploitation remains significant. The attack vector is inferred to be remote, requiring the attacker to interact with the application, for example via unsecured web endpoints or network services that accept file path input. If an attacker can supply a crafted path, they could read any file that the server process can access, leading to data exposure and potential further attacks.
OpenCVE Enrichment