CVE Published: 08/03/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: siemens |
Vendor: Siemens |
Product: SINUMERIK MC Status : PUBLISHED
CVE-2022-24408 Description
A vulnerability has been identified in SINUMERIK MC (All versions < V1.15 SP1), SINUMERIK ONE (All versions < V6.15 SP1). The sc SUID binary on affected devices provides several commands that are used to execute system commands or modify system files. A specific set of operations using sc could allow local attackers to escalate their privileges to root.