Siemens COMOS CVE-2013-4943 Local Privilege Escalation Vulnerability
BID:61704
Info
Siemens COMOS CVE-2013-4943 Local Privilege Escalation Vulnerability
| Bugtraq ID: | 61704 |
| Class: | Unknown |
| CVE: |
CVE-2013-4943 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 09 2013 12:00AM |
| Updated: | Aug 09 2013 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Siemens COMOS CVE-2013-4943 Local Privilege Escalation Vulnerability
Siemens COMOS is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to gain elevated privileges, which may aid in further attacks.
The following product versions are vulnerable:
COMOS versions prior to 9.1
COMOS 9.1 versions prior to 9.1 Update 458
COMOS 9.2 versions prior to 9.2.0.6.37
COMOS 10.0 versions prior to 10.0.3.0.19
Siemens COMOS is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to gain elevated privileges, which may aid in further attacks.
The following product versions are vulnerable:
COMOS versions prior to 9.1
COMOS 9.1 versions prior to 9.1 Update 458
COMOS 9.2 versions prior to 9.2.0.6.37
COMOS 10.0 versions prior to 10.0.3.0.19
Exploit / POC
Siemens COMOS CVE-2013-4943 Local Privilege Escalation Vulnerability
An attacker requires local access to the system as authenticated Windows user to exploit this issue.
An attacker requires local access to the system as authenticated Windows user to exploit this issue.
Solution / Fix
Siemens COMOS CVE-2013-4943 Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Siemens COMOS CVE-2013-4943 Local Privilege Escalation Vulnerability
References:
References:
- Siemens Homepage (Siemens)