CVE Database
/

CVE-2022-24408

Back to search

CVE-2022-24408

Published: Mar 8, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

A vulnerability has been identified in SINUMERIK MC (All versions < V1.15 SP1), SINUMERIK ONE (All versions < V6.15 SP1). The sc SUID binary on affected devices provides several commands that are used to execute system commands or modify system files. A specific set of operations using sc could allow local attackers to escalate their privileges to root.

VendorProductVersions

Siemens

SINUMERIK MC

affected
All versions < V1.15 SP1

Siemens

SINUMERIK ONE

affected
All versions < V6.15 SP1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now