A vulnerability has been identified in SICAM PAS/PQS (All versions >= V8.00 < V8.20). The affected application is installed with specific files and folders with insecure permissions. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges to `NT AUTHORITY/SYSTEM`.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-035466.pdf | patch vendor advisory |
https://cert-portal.siemens.com/productcert/html/ssa-035466.html |