Lucene search

K
cvelistSiemensCVELIST:CVE-2021-41544
HistoryAug 08, 2023 - 9:20 a.m.

CVE-2021-41544

2023-08-0809:20:08
CWE-427
siemens
www.cve.org
8
siemens
software center
vulnerability
versions
local attacker
dll hijacking
code execution
elevated privileges
directories

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C

AI Score

7.7

Confidence

High

EPSS

0

Percentile

5.1%

A vulnerability has been identified in Siemens Software Center (All versions < V3.0). A DLL Hijacking vulnerability could allow a local attacker to execute code with elevated privileges by placing a malicious DLL in one of the directories on the DLL search path.

CNA Affected

[
  {
    "vendor": "Siemens",
    "product": "Siemens Software Center",
    "versions": [
      {
        "version": "All versions < V3.0",
        "status": "affected"
      }
    ],
    "defaultStatus": "unknown"
  }
]

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C

AI Score

7.7

Confidence

High

EPSS

0

Percentile

5.1%

Related for CVELIST:CVE-2021-41544