Lucene search

K
nvd[email protected]NVD:CVE-2022-43514
HistoryJan 10, 2023 - 12:15 p.m.

CVE-2022-43514

2023-01-1012:15:23
CWE-22
web.nvd.nist.gov
8
vulnerability
automation license manager
telecontrol server basic
remote code execution
file operations
unauthenticated attackers

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.1

Confidence

High

EPSS

0.03

Percentile

91.1%

A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6 (All versions < V6.0 SP9 Upd4), TeleControl Server Basic V3 (All versions < V3.1.2). The affected component does not correctly validate the root path on folder related operations, allowing to modify files and folders outside the intended root directory.
This could allow an unauthenticated remote attacker to execute file operations of files outside of the specified root folder. Chained with CVE-2022-43513 this could allow Remote Code Execution.

Affected configurations

Nvd
Node
siemensautomation_license_managerMatch5.0.0
OR
siemensautomation_license_managerMatch5.1
OR
siemensautomation_license_managerMatch5.1sp1
OR
siemensautomation_license_managerMatch5.2
OR
siemensautomation_license_managerMatch5.3
OR
siemensautomation_license_managerMatch5.3sp3
OR
siemensautomation_license_managerMatch5.3.4.4
OR
siemensautomation_license_managerMatch6.0
OR
siemensautomation_license_managerMatch6.0.1
OR
siemensautomation_license_managerMatch6.0.8
OR
siemensautomation_license_managerMatch6.0.9
VendorProductVersionCPE
siemensautomation_license_manager5.0.0cpe:2.3:a:siemens:automation_license_manager:5.0.0:*:*:*:*:*:*:*
siemensautomation_license_manager5.1cpe:2.3:a:siemens:automation_license_manager:5.1:*:*:*:*:*:*:*
siemensautomation_license_manager5.1cpe:2.3:a:siemens:automation_license_manager:5.1:sp1:*:*:*:*:*:*
siemensautomation_license_manager5.2cpe:2.3:a:siemens:automation_license_manager:5.2:*:*:*:*:*:*:*
siemensautomation_license_manager5.3cpe:2.3:a:siemens:automation_license_manager:5.3:*:*:*:*:*:*:*
siemensautomation_license_manager5.3cpe:2.3:a:siemens:automation_license_manager:5.3:sp3:*:*:*:*:*:*
siemensautomation_license_manager5.3.4.4cpe:2.3:a:siemens:automation_license_manager:5.3.4.4:*:*:*:*:*:*:*
siemensautomation_license_manager6.0cpe:2.3:a:siemens:automation_license_manager:6.0:*:*:*:*:*:*:*
siemensautomation_license_manager6.0.1cpe:2.3:a:siemens:automation_license_manager:6.0.1:*:*:*:*:*:*:*
siemensautomation_license_manager6.0.8cpe:2.3:a:siemens:automation_license_manager:6.0.8:*:*:*:*:*:*:*
Rows per page:
1-10 of 111

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.1

Confidence

High

EPSS

0.03

Percentile

91.1%

Related for NVD:CVE-2022-43514