CVE-2022-23450

CRITICAL

Siemens Simatic Energy Manager Basic < 7.3 - Insecure Deserialization

Title source: rule

Description

A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1). The affected system allows remote users to send maliciously crafted objects. Due to insecure deserialization of user-supplied content by the affected software, an unauthenticated attacker could exploit this vulnerability by sending a maliciously crafted serialized object. This could allow the attacker to execute arbitrary code on the device with SYSTEM privileges.

Scores

CVSS v3 9.8
EPSS 0.3334
EPSS Percentile 96.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (4)

siemens/simatic_energy_manager_basic < 7.3
siemens/simatic_energy_manager_basic
siemens/simatic_energy_manager_pro < 7.3
siemens/simatic_energy_manager_pro

Timeline

Published Apr 12, 2022
Tracked Since Feb 18, 2026