CVE-2022-23450: Critical severity siemens simatic energy manager basic vulnerability
A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1). The affected system allows remote users to send maliciously crafted objects. Due to insecure deserialization of user-supplied content by the affected software, an unauthenticated attacker could exploit this vulnerability by sending a maliciously crafted serialized object. This could allow the attacker to execute arbitrary code on the device with SYSTEM privileges.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-23450?
CVE-2022-23450 is rated as a critical vulnerability due to the potential for remote code execution.
How do I fix CVE-2022-23450?
To fix CVE-2022-23450, update your Siemens SIMATIC Energy Manager Basic and PRO to version 7.3 Update 1 or later.
Which versions are affected by CVE-2022-23450?
CVE-2022-23450 affects all versions of Siemens SIMATIC Energy Manager Basic and PRO prior to version 7.3 Update 1.
What type of exploitation is associated with CVE-2022-23450?
CVE-2022-23450 can be exploited by remote users sending maliciously crafted objects due to insecure deserialization.
Is there a workaround for CVE-2022-23450?
There are no known workarounds for CVE-2022-23450, so applying the update is the recommended action.