CVE-2022-35868
published 2023-02-14CVE-2022-35868: A vulnerability has been identified in TIA Multiuser Server V14 (All versions), TIA Multiuser Server V15 (All versions < V15.1 Update 8), TIA Project-Server…
PriorityP336high7.3CVSS 3.1
AVLACLPRLUIRSUCHIHAH
EPSS
0.19%
9.0th percentile
A vulnerability has been identified in TIA Multiuser Server V14 (All versions), TIA Multiuser Server V15 (All versions < V15.1 Update 8), TIA Project-Server (All versions < V1.1), TIA Project-Server V16 (All versions), TIA Project-Server V17 (All versions < V17 Update 6). Affected applications contain an untrusted search path vulnerability that could allow an attacker to escalate privileges, when tricking a legitimate user to start the service from an attacker controlled path.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | tia_multiuser_server | — | — |
| siemens | tia_multiuser_server | — | — |
| siemens | tia_multiuser_server | — | — |
| siemens | tia_multiuser_server | — | — |
| siemens | tia_multiuser_server_v14 | < * | * |
| siemens | tia_multiuser_server_v15 | — | — |
| siemens | tia_project-server | — | — |
| siemens | tia_project-server | — | — |
| siemens | tia_project-server | — | — |
| siemens | tia_project-server_v16 | < * | * |
| siemens | tia_project-server_v17 | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens TIA Project-Server formerly known as TIA Multiuser Server
cisa_ics·2023-02-16·CVSS 6.7
[MEDIUM] Siemens TIA Project-Server formerly known as TIA Multiuser Server
ICS Advisory
##
Siemens TIA Project-Server formerly known as TIA Multiuser Server
Release DateFebruary 16, 2023
Alert CodeICSA-23-047-07
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 6.7
- ATTENTION: High attack complexity
- Vendor: Siemens
- Equipment: TIA Project-Server
- Vulnerability: Untrusted Search Path
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to escalate privileges when tricking a legitimate user to s
GHSA
GHSA-5qx2-5w4h-wgr8: A vulnerability has been identified in TIA Multiuser Server V14 (All versions), TIA Multiuser Server V15 (All versions < V15
ghsa_unreviewed·2023-02-14
CVE-2022-35868 [HIGH] CWE-426 GHSA-5qx2-5w4h-wgr8: A vulnerability has been identified in TIA Multiuser Server V14 (All versions), TIA Multiuser Server V15 (All versions < V15
A vulnerability has been identified in TIA Multiuser Server V14 (All versions), TIA Multiuser Server V15 (All versions < V15.1 Update 8), TIA Project-Server (All versions < V1.1), TIA Project-Server V16 (All versions), TIA Project-Server V17 (All versions). Affected applications contain an untrusted search path vulnerability that could allow an attacker to escalate privileges, when tricking a legitimate user to start the service from an attacker controlled path.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-02-14
Published