Code Execution Flaw in Siemens License Server Affects All Versions Before 4.3
CVE-2025-29999
5.4MEDIUM
Summary
A flaw has been identified in Siemens License Server that permits execution of arbitrary code with administrative privileges. This vulnerability arises from the application's inadequate validation when searching for executable files within its own directory. An attacker can exploit this weakness by placing a malicious executable in the application folder, potentially compromising the system's security.
Affected Version(s)
Siemens License Server (SLS) 0
References
CVSS V4
Score:
5.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved