7.8
CVSSv3

CVE-2022-24408

Published: 08/03/2022 Updated: 11/03/2022
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

A vulnerability has been identified in SINUMERIK MC (All versions < V1.15 SP1), SINUMERIK ONE (All versions < V6.15 SP1). The sc SUID binary on affected devices provides several commands that are used to execute system commands or modify system files. A specific set of operations using sc could allow local malicious users to escalate their privileges to root.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

siemens sinumerik mc firmware

siemens sinumerik mc firmware 1.15

siemens sinumerik one firmware

siemens sinumerik one firmware 6.15

ICS Advisories

Siemens SINUMERIK MC
Critical Infrastructure Sectors: Critical Manufacturing