A vulnerability has been identified in Siemens SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate user input to the ssmctl-client command.
This could allow an authenticated, lowly privileged remote attacker to execute arbitrary code with root privileges on the underlying OS.
| Software | From | Fixed in |
|---|---|---|
| siemens / sinec_security_monitor | - | 4.9.0 |