CVE-2023-45205: High severity siemens sicam pas/pqs vulnerability
A vulnerability has been identified in SICAM PAS/PQS (All versions >= V8.00 < V8.20). The affected application is installed with specific files and folders with insecure permissions. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges to NT AUTHORITY/SYSTEM.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-45205?
The severity of CVE-2023-45205 is high with a severity value of 7.8.
Which versions of SICAM PAS/PQS are affected by CVE-2023-45205?
All versions greater than or equal to V8.00 and less than V8.20 of SICAM PAS/PQS are affected by CVE-2023-45205.
What is the vulnerability description of CVE-2023-45205?
CVE-2023-45205 is a vulnerability in SICAM PAS/PQS where specific files and folders have insecure permissions, allowing an authenticated local attacker to inject arbitrary code and escalate privileges.
How can an attacker exploit CVE-2023-45205?
An attacker with local access can exploit CVE-2023-45205 by injecting arbitrary code and escalating privileges on the affected system.
Is there a fix for CVE-2023-45205?
Yes, Siemens has provided a security advisory with mitigation measures to address the vulnerability described in CVE-2023-45205.