VDB
CISA-2024-47562
CISA-2024-47562
PUBLISHED
CVSS 8.8 HIGH
Reported by siemens · Published October 8, 2024
A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly neutralize special elements in user input to the ```ssmctl-client``` command. This could allow an authenticated, lowly privileged local attacker to execute privileged commands in the underlying OS.
Risk Scores
CVSS 3.1
8.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | SINEC Security Monitor | 0 |
| Siemens | SINEC Security Monitor | 0, 0 |
| siemens | sinec_security_monitor | 0, 0 |
Timeline
- Oct 8, 2024 CVE Published
- Mar 10, 2026 CVE Updated