Remote Code Execution Vulnerability in Desigo CC by Siemens
CVE-2024-23815
8.7HIGH
What is CVE-2024-23815?
A vulnerability exists in the Desigo CC server application that could allow unauthenticated attackers to execute arbitrary SQL queries on the server database. This issue arises when access from installed clients to the Desigo CC server is permitted from less secure networks, or even within highly protected zones if specific security measures are not adequately enforced. By modifying the client binary, attackers can exploit the system through the event port (default: 4998/tcp), posing a significant risk to the integrity and confidentiality of the server's data.
Affected Version(s)
Desigo CC 0
Desigo CC 0