9.8
CVSSv3

CVE-2022-23450

Published: 12/04/2022 Updated: 19/04/2022
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 891
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1). The affected system allows remote users to send maliciously crafted objects. Due to insecure deserialization of user-supplied content by the affected software, an unauthenticated attacker could exploit this vulnerability by sending a maliciously crafted serialized object. This could allow the malicious user to execute arbitrary code on the device with SYSTEM privileges.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

siemens simatic energy manager basic

siemens simatic energy manager basic 7.3

siemens simatic energy manager pro

siemens simatic energy manager pro 7.3

ICS Advisories

Siemens SIMATIC Energy Manager
Critical Infrastructure Sectors: Energy