CVE-2021-37207

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/11/2021
Last modified:
11/11/2021

Description

A vulnerability has been identified in SENTRON powermanager V3 (All versions). The affected application assigns improper access rights to a specific folder containing configuration files. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:siemens:sentron_powermanager_3:*:*:*:*:*:*:*:* 3.0 (including) 3.6 (including)


References to Advisories, Solutions, and Tools