A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6 (All versions < V6.0 SP9 Upd4), TeleControl Server Basic V3 (All versions < V3.1.2). The affected components allow to rename license files with user chosen input without authentication.
This could allow an unauthenticated remote attacker to rename and move files as SYSTEM user.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 07:26
Type | Values Removed | Values Added |
---|---|---|
References | () https://cert-portal.siemens.com/productcert/html/ssa-476715.html - | |
References | () https://cert-portal.siemens.com/productcert/html/ssa-556635.html - | |
References | () https://cert-portal.siemens.com/productcert/pdf/ssa-476715.pdf - Vendor Advisory | |
Summary |
|
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.2 |
09 Apr 2024, 09:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Summary | (en) A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6 (All versions < V6.0 SP9 Upd4), TeleControl Server Basic V3 (All versions < V3.1.2). The affected components allow to rename license files with user chosen input without authentication. This could allow an unauthenticated remote attacker to rename and move files as SYSTEM user. |
07 Nov 2023, 03:53
Type | Values Removed | Values Added |
---|---|---|
Summary | A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6 (All versions < V6.0 SP9 Upd4). The affected components allow to rename license files with user chosen input without authentication. This could allow an unauthenticated remote attacker to rename and move files as SYSTEM user. |
Information
Published : 2023-01-10 12:15
Updated : 2024-11-21 07:26
NVD link : CVE-2022-43513
Mitre link : CVE-2022-43513
CVE.ORG link : CVE-2022-43513
JSON object : View
Products Affected
siemens
- automation_license_manager