6.7
CVE-2022-35868
- EPSS 0.19%
- Veröffentlicht 14.02.2023 11:15:12
- Zuletzt bearbeitet 21.11.2024 07:11:50
- Erkennungen
A vulnerability has been identified in TIA Multiuser Server V14 (All versions), TIA Multiuser Server V15 (All versions < V15.1 Update 8), TIA Project-Server (All versions < V1.1), TIA Project-Server V16 (All versions), TIA Project-Server V17 (All versions < V17 Update 6). Affected applications contain an untrusted search path vulnerability that could allow an attacker to escalate privileges, when tricking a legitimate user to start the service from an attacker controlled path.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Siemens ≫ Tia Multiuser Server Version 14
Siemens ≫ Tia Multiuser Server Version 15
Siemens ≫ Tia Multiuser Server Version 15.1 Update -
Siemens ≫ Tia Multiuser Server Version 16
Siemens ≫ Tia Project-server Version 1.0
Siemens ≫ Tia Project-server Version 17 Update -
Siemens ≫ Tia Project-server Version 17 Update update1
Siemens ≫ Tia Project-server Version 17 Update update4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.19% | 0.09 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Siemens | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
|
| NIST | 7.3 | 1.3 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
|
CWE-426 Untrusted Search Path
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
https://cert-portal.siemens.com/productcert/html/ssa-640968.html
https://cert-portal.siemens.com/productcert/pdf/ssa-640968.pdf