CVE-2024-47553 PUBLISHED CVSS 9.899999618530273 CRITICAL

A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate user input to the ```ssmctl-client``` command. This could allow an authenticated, lowly privileged remote attacker to execute arbitrary code with root privileges on the underlying OS.

EPSS 3.03% · 86.5th percentile

Risk Scores

CVSS v3.1
9.899999618530273
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
EPSS Score
3.03%
86.5th percentile

Affected Products

VendorProductVersions
SiemensSINEC Security Monitor0, 0, 0
siemenssinec_security_monitor0, 0, 0
siemenssinec_security_monitor0, 0, 0

Timeline

References

Open in Interactive Console →