First published: Tue Oct 10 2023(Updated: )
A vulnerability has been identified in SICAM PAS/PQS (All versions >= V8.00 < V8.20). The affected application is installed with specific files and folders with insecure permissions. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges to `NT AUTHORITY/SYSTEM`.
Credit: productcert@siemens.com productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Sicam Pas\/pqs | >=8.00<8.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-45205 is high with a severity value of 7.8.
All versions greater than or equal to V8.00 and less than V8.20 of SICAM PAS/PQS are affected by CVE-2023-45205.
CVE-2023-45205 is a vulnerability in SICAM PAS/PQS where specific files and folders have insecure permissions, allowing an authenticated local attacker to inject arbitrary code and escalate privileges.
An attacker with local access can exploit CVE-2023-45205 by injecting arbitrary code and escalating privileges on the affected system.
Yes, Siemens has provided a security advisory with mitigation measures to address the vulnerability described in CVE-2023-45205.