A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1). Affected applications improperly assign permissions to critical directories and files used by the application processes. This could allow a local unprivileged attacker to achieve code execution with ADMINISTRATOR or even NT AUTHORITY/SYSTEM privileges.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Simatic_energy_manager_basic | Siemens | * | 7.3 (excluding) |
Simatic_energy_manager_basic | Siemens | 7.3 (including) | 7.3 (including) |
Simatic_energy_manager_pro | Siemens | * | 7.3 (excluding) |
Simatic_energy_manager_pro | Siemens | 7.3 (including) | 7.3 (including) |