« Volver al listado

CVE-2022-23449

Estado: ModificadaAlta (7.3)—

A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1). A DLL Hijacking vulnerability could allow a local attacker to execute code with elevated privileges by placing a malicious DLL in one of the directories on the DLL search path.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-23449",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.9,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.4,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.3,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.3
      }
    ]
  },
  "affected": [
    {
      "source": "productcert@siemens.com",
      "affectedData": [
        {
          "vendor": "Siemens",
          "product": "SIMATIC Energy Manager Basic",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V7.3 Update 1"
            }
          ]
        },
        {
          "vendor": "Siemens",
          "product": "SIMATIC Energy Manager PRO",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V7.3 Update 1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-04-12T09:15:14.297",
  "references": [
    {
      "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-655554.pdf",
      "tags": [
        "Mitigation",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "productcert@siemens.com"
    },
    {
      "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-655554.pdf",
      "tags": [
        "Mitigation",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "productcert@siemens.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-427"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-427"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1). A DLL Hijacking vulnerability could allow a local attacker to execute code with elevated privileges by placing a malicious DLL in one of the directories on the DLL search path."
    },
    {
      "lang": "es",
      "value": "Se ha identificado una vulnerabilidad en SIMATIC Energy Manager Basic (todas las versiones anteriores a V7.3 Update 1), SIMATIC Energy Manager PRO (todas las versiones anteriores a V7.3 Update 1). Una vulnerabilidad de DLL Hijacking podría permitir a un atacante local ejecutar código con altos privilegios al colocar una DLL maliciosa en uno de los directorios de la ruta de búsqueda de DLL"
    }
  ],
  "lastModified": "2026-06-17T04:30:08.720",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:siemens:simatic_energy_manager_basic:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2BDBCB2C-E9EB-4AF6-B47A-22B27AE41178",
              "versionEndExcluding": "7.3"
            },
            {
              "criteria": "cpe:2.3:a:siemens:simatic_energy_manager_basic:7.3:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1BB78E93-7C0A-4F59-B6EA-3D5A681BFE8F"
            },
            {
              "criteria": "cpe:2.3:a:siemens:simatic_energy_manager_pro:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4B1E608C-3C6F-45FB-86C9-E99E7F21836D",
              "versionEndExcluding": "7.3"
            },
            {
              "criteria": "cpe:2.3:a:siemens:simatic_energy_manager_pro:7.3:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "34A11AF9-7F0C-4151-8A4D-A8E1BDCBA525"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "productcert@siemens.com"
}