← Back

CVE-2022-35868

nvd nist
Published: Feb 14, 2023Modified: Nov 21, 2024

JSON object

Loading...
7.3
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.3 / Impact: 5.9
Source: NVD (Secondary)

Description

A vulnerability has been identified in TIA Multiuser Server V14 (All versions), TIA Multiuser Server V15 (All versions < V15.1 Update 8), TIA Project-Server (All versions < V1.1), TIA Project-Server V16 (All versions), TIA Project-Server V17 (All versions < V17 Update 6). Affected applications contain an untrusted search path vulnerability that could allow an attacker to escalate privileges, when tricking a legitimate user to start the service from an attacker controlled path.

Affected (8)

2 products
Tia Multiuser Server
Tia Project Server
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Siemens
Version 14
Version 15.1
Version 15
Version 16
Siemens
Version 1.0
Version 17
Version 17 update1
Version 17 update4

References (3)

Source: productcert@siemens.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.