Our takeSiemens patched multiple flaws in its License Server: a local attacker could escalate privileges and read arbitrary files. SLS ships alongside many Siemens engineering tools, so it's easy to forget you run it. Check for it and update to the latest version.Cyber Resilience desk
Sources (1)
- cisa_ics · cisa_ics
What this means for you — Security leader:Update to the latest Siemens License Server version to address privilege escalation and arbitrary file read vulnerabilities.
What this means for you — Lean IT orgs:If you run Siemens License Server, update it to the newest version right away; most teams without it can ignore this.
What this means for you — MSP:Check client environments for Siemens License Server deployments and push the latest version to remediate privilege escalation and file-read risks.
What this means for you — Researcher:Siemens has released an updated License Server version addressing multiple privilege-escalation and arbitrary-file-read flaws.