7.8
CVSSv3

CVE-2022-23448

Published: 12/04/2022 Updated: 19/04/2022
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 642
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1). Affected applications improperly assign permissions to critical directories and files used by the application processes. This could allow a local unprivileged malicious user to achieve code execution with ADMINISTRATOR or even NT AUTHORITY/SYSTEM privileges.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

siemens simatic energy manager basic

siemens simatic energy manager basic 7.3

siemens simatic energy manager pro

siemens simatic energy manager pro 7.3

ICS Advisories

Siemens SIMATIC Energy Manager
Critical Infrastructure Sectors: Energy