Siemens Automation License Manager (ALM) before 5.3 SP3 allows remote attackers to write to files, rename files, create directories, or delete directories via crafted packets.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-16-287-02 | |
http://www.securitytracker.com/id/1037011 | vdb entry |
http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-284342.pdf | patch vendor advisory |
http://www.securityfocus.com/bid/93553 | vdb entry third party advisory |