PT-2026-24223 · Siemens+1 · Sicam Siapp Sdk
CVE-2026-25573
·
Publicado
2026-03-10
·
Atualizado
2026-03-18
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SICAM SIAPP SDK versions prior to 2.1.7
Description
The application constructs shell commands using strings provided by the user and then executes these commands. This can allow an attacker to manipulate the executed command, potentially leading to command injection and complete system compromise. The application improperly handles external control of file names or paths, which could allow an attacker to execute arbitrary commands.
Recommendations
Update SICAM SIAPP SDK to version 2.1.7 or later.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sicam Siapp Sdk