CVE Published: 12/04/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: siemens |
Vendor: Siemens |
Product: SIMATIC Energy Manager Basic Status : PUBLISHED
CVE-2022-23448 Description
A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1). Affected applications improperly assign permissions to critical directories and files used by the application processes. This could allow a local unprivileged attacker to achieve code execution with ADMINISTRATOR or even NT AUTHORITY/SYSTEM privileges.