CVE-2022-35868: High severity siemens tia multiuser server vulnerability
A vulnerability has been identified in TIA Multiuser Server V14 (All versions), TIA Multiuser Server V15 (All versions < V15.1 Update 8), TIA Project-Server (All versions < V1.1), TIA Project-Server V16 (All versions), TIA Project-Server V17 (All versions < V17 Update 6). Affected applications contain an untrusted search path vulnerability that could allow an attacker to escalate privileges, when tricking a legitimate user to start the service from an attacker controlled path.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-35868?
CVE-2022-35868 has been classified with a medium severity level due to potential impact on system integrity.
How do I fix CVE-2022-35868?
To mitigate CVE-2022-35868, update the affected software to the latest version as specified by Siemens.
Which versions of Siemens TIA Multiuser Server are affected by CVE-2022-35868?
Versions 14, 15 (all versions before V15.1 Update 8), and 16 of Siemens TIA Multiuser Server are vulnerable to CVE-2022-35868.
Are earlier versions of TIA Project-Server affected by CVE-2022-35868?
Yes, all versions of TIA Project-Server prior to V1.1 and versions 16 and 17 (all versions before V17 Update 6) are affected by CVE-2022-35868.
What type of vulnerability is CVE-2022-35868?
CVE-2022-35868 is identified as a software vulnerability that can compromise system security in the specified Siemens TIA applications.