SQL Injection Vulnerability in Siemens Automation License Manager
CVE-2016-8564

6.5MEDIUM

Key Information:

Vendor
Siemens
Vendor
CVE Published:
13 October 2016

Summary

The SQL injection vulnerability in Siemens Automation License Manager allows remote attackers to execute arbitrary SQL commands by sending specially crafted traffic to TCP port 4410. This could potentially lead to unauthorized access to sensitive data within the system. It is essential for organizations using affected versions of the Automation License Manager to assess their security posture and apply the necessary updates to mitigate this vulnerability.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.