Improper Neutralization in Siemens Desigo Products
CVE-2022-40176

8HIGH

Key Information:

Vendor
Siemens
Vendor
CVE Published:
11 October 2022

Summary

A vulnerability exists in Siemens Desigo products that allows for improper neutralization of special elements in an OS command during restoration operations. This weakness stems from inadequate validation of file names within the input package. A remote, low-privileged attacker can exploit this vulnerability by restoring a meticulously crafted package, thereby executing arbitrary system commands with root privileges. This could lead to complete system compromise, making timely remediation essential.

Affected Version(s)

Desigo PXM30-1 All versions < V02.20.126.11-41

Desigo PXM30.E All versions < V02.20.126.11-41

Desigo PXM40-1 All versions < V02.20.126.11-41

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.