#VU62387 Incorrect permission assignment for critical resource in SIMATIC Energy Manager Basic and SIMATIC Energy Manager PRO - CVE-2022-23448
Published: April 19, 2022 / Updated: September 14, 2022
SIMATIC Energy Manager Basic
SIMATIC Energy Manager PRO
Siemens
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to the affected application assigns permissions to critical directories and files used by the application processes. A local user can execute arbitrary code on the system with elevated privileges.