DLL Hijacking Vulnerability in SIMATIC Energy Manager Products by Siemens
CVE-2022-23449
7.3HIGH
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 12 April 2022
What is CVE-2022-23449?
A vulnerability exists in Siemens' SIMATIC Energy Manager Basic and PRO products that allows local attackers to exploit DLL hijacking. By placing a malicious DLL in a directory included in the DLL search path, attackers can execute code with elevated privileges. This poses significant risks to the security and integrity of the system, emphasizing the need for prompt updates and mitigations.
Affected Version(s)
SIMATIC Energy Manager Basic All versions < V7.3 Update 1
SIMATIC Energy Manager PRO All versions < V7.3 Update 1