Siemens SIMATIC IPC DiagBase
cpe:2.3:h:siemens:simatic_ipc_diagbase:*:*:*:*:*:*:*, +1 more
A vulnerability exists in all versions of Siemens SIMATIC IPC DiagBase and SIMATIC IPC DiagMonitor due to improper restriction of user permissions for a registry key. This flaw could enable an authenticated attacker to load vulnerable drivers into the system, potentially leading to privilege escalation or bypassing endpoint protection and other security measures.
Exploitation of this vulnerability could result in unauthorized privilege escalation or the ability to bypass security measures such as endpoint protection.
Users can manually modify the registry to remove the user privilege or run a script for the same purpose. For more information, refer to the Siemens support document 109978178. Currently, no fix is planned for this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.