Siemens OZW672
cpe:2.3:h:siemens:ozw672:*:*:*:*:*:*:*, +1 more
- < V8.0
A code execution vulnerability has been identified in Siemens OZW672 and OZW772 web server versions prior to V8.0. The issue arises because the web service does not properly sanitize input parameters for the 'exportDiagramPage' endpoint. This lack of input validation could enable an unauthenticated remote attacker to execute arbitrary code with root privileges on the affected devices.
Exploitation of this vulnerability allows for arbitrary code execution with root privileges on the affected device.
Siemens has released new versions for the affected products. Users are advised to update to the latest versions. Product-specific update instructions can be found on the Siemens Support website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.