QID 590612
Date Published: 2021-12-08
QID 590612: Siemens SENTRON powermanager Incorrect Permission Assignment for Critical Resource Vulnerability (ICSA-21-315-10)
AFFECTED PRODUCTS
The following versions of Siemens SENTRON powermanager, a power monitoring software to analyze energy consumption, are affected:
SENTRON powermanager Version 3: All versions
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of Siemens using registry "HKLM\SOFTWARE\Siemens"
Note: As we are unable to check for the patch mentioned so making this a Potential check.
Successful exploitation of this vulnerability could allow an authenticated local attacker to inject arbitrary code and escalate privileges.
Solution
Customers are advised to refer to CERT MITIGATIONS section ICSA-21-315-10 for affected packages and patching details.
Vendor References
- ICSA-21-315-10 -
www.us-cert.gov/ics/advisories/ICSA-21-315-10
CVEs related to QID 590612
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ICSA-21-315-10 |
|