| Publication Date: |
2021-09-14 |
| Last Update: |
2021-10-12 |
| Current Version: |
V1.1 |
| CVSS v3.1 Base Score: |
8.8 |
- Apply the principle of least privileges for accounts configured on the affected devices
| CVSS v3.1 Base Score |
8.8 |
| CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C |
| CWE: |
CWE-269: Improper Privilege Management |
| CVSS v3.1 Base Score |
8.8 |
| CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C |
| CWE: |
CWE-250: Execution with Unnecessary Privileges |
| CVSS v3.1 Base Score |
4.3 |
| CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C |
| CWE: |
CWE-280: Improper Handling of Insufficient Permissions or Privileges |
-
Michael Messner from
Siemens Energy
for reporting the vulnerabilities
https://www.siemens.com/cert/advisories