VDB

CISA-2024-47553

CISA-2024-47553 PUBLISHED CVSS 9.9 CRITICAL

Reported by siemens · Published October 8, 2024

A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate user input to the ```ssmctl-client``` command. This could allow an authenticated, lowly privileged remote attacker to execute arbitrary code with root privileges on the underlying OS.

Risk Scores

CVSS 3.1
9.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C

Affected Products

VendorProductVersions
SiemensSINEC Security Monitor0
siemenssinec_security_monitor0, 0
SiemensSINEC Security Monitor0, 0

Timeline

  • Oct 8, 2024 CVE Published
  • Mar 10, 2026 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›