// For flags

CVE-2022-24408

 

Severity Score

7.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A vulnerability has been identified in SINUMERIK MC (All versions < V1.15 SP1), SINUMERIK ONE (All versions < V6.15 SP1). The sc SUID binary on affected devices provides several commands that are used to execute system commands or modify system files. A specific set of operations using sc could allow local attackers to escalate their privileges to root.

Se ha identificado una vulnerabilidad en SINUMERIK MC (Todas las versiones anteriores a la versión V1.15 SP1), SINUMERIK ONE (Todas las versiones anteriores a la versión V6.15 SP1). El binario sc SUID en los dispositivos afectados proporciona varios comandos que se utilizan para ejecutar comandos del sistema o modificar archivos del sistema. Un conjunto específico de operaciones utilizando sc podría permitir a los atacantes locales escalar sus privilegios a root

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-02-04 CVE Reserved
  • 2022-03-08 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-269: Improper Privilege Management
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Siemens
Search vendor "Siemens"
Sinumerik Mc Firmware
Search vendor "Siemens" for product "Sinumerik Mc Firmware"
< 1.15
Search vendor "Siemens" for product "Sinumerik Mc Firmware" and version " < 1.15"
-
Affected
in Siemens
Search vendor "Siemens"
Sinumerik Mc
Search vendor "Siemens" for product "Sinumerik Mc"
--
Safe
Siemens
Search vendor "Siemens"
Sinumerik Mc Firmware
Search vendor "Siemens" for product "Sinumerik Mc Firmware"
1.15
Search vendor "Siemens" for product "Sinumerik Mc Firmware" and version "1.15"
-
Affected
in Siemens
Search vendor "Siemens"
Sinumerik Mc
Search vendor "Siemens" for product "Sinumerik Mc"
--
Safe
Siemens
Search vendor "Siemens"
Sinumerik One Firmware
Search vendor "Siemens" for product "Sinumerik One Firmware"
< 6.15
Search vendor "Siemens" for product "Sinumerik One Firmware" and version " < 6.15"
-
Affected
in Siemens
Search vendor "Siemens"
Sinumerik One
Search vendor "Siemens" for product "Sinumerik One"
--
Safe
Siemens
Search vendor "Siemens"
Sinumerik One Firmware
Search vendor "Siemens" for product "Sinumerik One Firmware"
6.15
Search vendor "Siemens" for product "Sinumerik One Firmware" and version "6.15"
-
Affected
in Siemens
Search vendor "Siemens"
Sinumerik One
Search vendor "Siemens" for product "Sinumerik One"
--
Safe