A vulnerability has been identified in Siemens SINEC...
Critical severity
Unreviewed
Published
Oct 8, 2024
to the GitHub Advisory Database
•
Updated Oct 8, 2024
Description
Published by the National Vulnerability Database
Oct 8, 2024
Published to the GitHub Advisory Database
Oct 8, 2024
Last updated
Oct 8, 2024
A vulnerability has been identified in Siemens SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate user input to the
ssmctl-client
command.This could allow an authenticated, lowly privileged remote attacker to execute arbitrary code with root privileges on the underlying OS.
References