VDB

CISA-2024-47562

CISA-2024-47562 PUBLISHED CVSS 8.8 HIGH

Reported by siemens · Published October 8, 2024

A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly neutralize special elements in user input to the ```ssmctl-client``` command. This could allow an authenticated, lowly privileged local attacker to execute privileged commands in the underlying OS.

Risk Scores

CVSS 3.1
8.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C

Affected Products

VendorProductVersions
SiemensSINEC Security Monitor0
SiemensSINEC Security Monitor0, 0
siemenssinec_security_monitor0, 0

Timeline

  • Oct 8, 2024 CVE Published
  • Mar 10, 2026 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›