QID 591164
Date Published: 2022-11-07
QID 591164: Siemens SIMATIC NET PC Software Unquoted Search Path Vulnerability (SSA-312271)
AFFECTED PRODUCTS
The following Siemens products are affected:
SIMATIC NET PC Software V14: All versions prior to V14 SP1 Update 14
SIMATIC NET PC Software V15: All versions
SIMATIC NET PC Software: V16 All versions prior to V16 Update 3
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of Siemens using registry "HKLM\SOFTWARE\Siemens"
Successful exploitation of this vulnerability allows authorized local users with administrative privileges to execute custom code with SYSTEM-level privileges.
Solution
Customers are advised to refer to CERT MITIGATIONS section SSA-312271 for affected packages and patching details.
Vendor References
CVEs related to QID 591164
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SSA-312271 |
|