CVE-2024-47553
CVSS 3.1 Score 9.9 of 10 (high)
Details
Published Oct 8, 2024
Updated: Oct 11, 2024
CWE ID 88
Summary
CVE-2024-47553 is a newly discovered vulnerability that affects Siemens SINEC Security Monitor versions below V4.9.0. The issue lies in the inadequate validation of user inputs to the "ssmctl-client" command. An authenticated, low-privileged remote attacker can take advantage of this flaw, leading to the execution of arbitrary code with root privileges on the underlying OS. This vulnerability poses a significant risk and requires immediate attention and patching from system administrators.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.