Siemens Automation License Manager是德国西门子(Siemens)公司的一款用于Siemens产品的许可证管理器。 Siemens Automation License Manager存在路径遍历漏洞,该漏洞源于无法正确验证文件夹相关操作的根路径,从而允许修改预期根目录之外的文件和文件夹,可能允许未经身份验证的远程攻击者对指定根文件夹之外的文件执行文件操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Siemens | Automation License Manager V5 | 0 ~ * | - |
|
| Siemens | Automation License Manager V6 | All versions < V6.0 SP9 Upd4 | - |
|
| Siemens | TeleControl Server Basic V3 | 0 ~ V3.1.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-45092 | 9.9 CRITICAL | Siemens SINEC NMS 路径遍历漏洞 |
| CVE-2022-46823 | 9.3 CRITICAL | Siemens Mendix 跨站脚本漏洞 |
| CVE-2022-45093 | 8.5 HIGH | Siemens SINEC NMS 路径遍历漏洞 |
| CVE-2022-45094 | 8.4 HIGH | Siemens SINEC NMS 命令注入漏洞 |
| CVE-2022-43513 | 8.2 HIGH | Siemens Automation License Manager 安全漏洞 |
| CVE-2022-47967 | 7.8 HIGH | Siemens Solid Edge 缓冲区错误漏洞 |
| CVE-2022-47935 | 7.8 HIGH | Siemens JT Open Toolkit 缓冲区错误漏洞 |
| CVE-2022-38773 | 4.6 MEDIUM | Siemens SIMATIC S7-1500 安全漏洞 |
No comments yet