DLL Hijacking Vulnerability in SIMATIC Energy Manager Products by Siemens
CVE-2022-23449

7.3HIGH

Key Information:

Vendor
Siemens
Vendor
CVE Published:
12 April 2022

Summary

A vulnerability exists in Siemens' SIMATIC Energy Manager Basic and PRO products that allows local attackers to exploit DLL hijacking. By placing a malicious DLL in a directory included in the DLL search path, attackers can execute code with elevated privileges. This poses significant risks to the security and integrity of the system, emphasizing the need for prompt updates and mitigations.

Affected Version(s)

SIMATIC Energy Manager Basic All versions < V7.3 Update 1

SIMATIC Energy Manager PRO All versions < V7.3 Update 1

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
🍪 This website uses cookies, like every other website on the internet 😕 By using our website, you consent to the use of cookies.