← Back to CVEs
CVE-2021-45460
HIGH8.1
Description
A vulnerability has been identified in SICAM PQ Analyzer (All versions < V3.18). A service is started by an unquoted registry entry. As there are spaces in this path, attackers with write privilege to those directories might be able to plant executables that will run in place of the legitimate process. Attackers might achieve persistence on the system ("backdoors") or cause a denial of service.
CVE Details
CVSS v3.1 Score8.1
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
Published1/11/2022
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
siemens:sicam_pq_analyzersiemens:sicam_pq_analyzer_firmware
Weaknesses (CWE)
CWE-428CWE-428
References
https://cert-portal.siemens.com/productcert/pdf/ssa-173318.pdf(productcert@siemens.com)
https://cert-portal.siemens.com/productcert/pdf/ssa-173318.pdf(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.