DLL Hijacking Vulnerability in SIMATIC Energy Manager Products by Siemens
CVE-2022-23449
7.3HIGH
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 12 April 2022
Summary
A vulnerability exists in Siemens' SIMATIC Energy Manager Basic and PRO products that allows local attackers to exploit DLL hijacking. By placing a malicious DLL in a directory included in the DLL search path, attackers can execute code with elevated privileges. This poses significant risks to the security and integrity of the system, emphasizing the need for prompt updates and mitigations.
Affected Version(s)
SIMATIC Energy Manager Basic All versions < V7.3 Update 1
SIMATIC Energy Manager PRO All versions < V7.3 Update 1
References
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved