First published: Tue Nov 09 2021(Updated: )
A vulnerability has been identified in SENTRON powermanager V3 (All versions). The affected application assigns improper access rights to a specific folder containing configuration files. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Sentron Powermanager | >=3.0<=3.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-37207 is classified as a high-severity vulnerability due to its potential to allow privilege escalation.
To mitigate CVE-2021-37207, ensure that proper access rights are enforced on the configuration files folder.
CVE-2021-37207 affects all versions of Siemens SENTRON Powermanager V3.
CVE-2021-37207 requires local authenticated access for an attacker to exploit the vulnerability.
CVE-2021-37207 allows an authenticated local attacker to inject arbitrary code and escalate privileges.