A vulnerability has been identified in Siemens SINEC...
Critical severity
Unreviewed
Published
Oct 8, 2024
to the GitHub Advisory Database
•
Updated Oct 8, 2024
Description
Published by the National Vulnerability Database
Oct 8, 2024
Published to the GitHub Advisory Database
Oct 8, 2024
Last updated
Oct 8, 2024
A vulnerability has been identified in Siemens SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly neutralize special elements in user input to the
ssmctl-client
command.This could allow an authenticated, lowly privileged local attacker to execute privileged commands in the underlying OS.
References