Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-23450

Опубликовано: 12 апр. 2022
Источник: nvd
CVSS3: 9.8
CVSS2: 10
EPSS Средний

Описание

A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1). The affected system allows remote users to send maliciously crafted objects. Due to insecure deserialization of user-supplied content by the affected software, an unauthenticated attacker could exploit this vulnerability by sending a maliciously crafted serialized object. This could allow the attacker to execute arbitrary code on the device with SYSTEM privileges.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:siemens:simatic_energy_manager_basic:*:*:*:*:*:*:*:*
Версия до 7.3 (исключая)
cpe:2.3:a:siemens:simatic_energy_manager_basic:7.3:-:*:*:*:*:*:*
cpe:2.3:a:siemens:simatic_energy_manager_pro:*:*:*:*:*:*:*:*
Версия до 7.3 (исключая)
cpe:2.3:a:siemens:simatic_energy_manager_pro:7.3:-:*:*:*:*:*:*

EPSS

Процентиль: 97%
0.33344
Средний

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-502
CWE-502

Связанные уязвимости

CVSS3: 9.8
github
почти 4 года назад

A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1). The affected system allows remote users to send maliciously crafted objects. Due to insecure deserialization of user-supplied content by the affected software, an unauthenticated attacker could exploit this vulnerability by sending a maliciously crafted serialized object. This could allow the attacker to execute arbitrary code on the device with SYSTEM privileges.

CVSS3: 10
fstec
почти 4 года назад

Уязвимость программного средства системы энергоменеджмента SIMATIC Energy Manager Basic и SIMATIC Energy Manager PRO, связанная с восстановлением в памяти недостоверных данных, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 97%
0.33344
Средний

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-502
CWE-502