Zum Hauptinhalt springen
•••••••
Windows Tipps & Securityfoobar2000(03.10.2026 um 09:00 Uhr)
••••••••••
Windows Tipps & Securityfoobar2000(03.10.2026 um 09:00 Uhr)
•••
Intelligence View
⚡ tsecurity.de Intelligence

Siemens License Server

As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most…

Beitrag
0
Seite
0
↗ Quelle (cisa.gov)
Social ReaktionenReagiere als Erste:r — dein Feedback zählt!

As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).


View CSAF


1. EXECUTIVE SUMMARY



  • CVSS v4 5.4

  • ATTENTION: Exploitable locally

  • Vendor: Siemens

  • Equipment: License Server

  • Vulnerabilities: Improper Privilege Management, Improper Certificate Validation


2. RISK EVALUATION


Successful exploitation of these vulnerabilities could allow a low-privileged local user to escalate privileges or perform arbitrary code execution.


3. TECHNICAL DETAILS


3.1 AFFECTED PRODUCTS


Siemens reports that the following products are affected:



  • License Server (SLS): All versions before V4.3


3.2 VULNERABILITY OVERVIEW


3.2.1 IMPROPER PRIVILEGE MANAGEMENT CWE-269


The affected application searches for executable files in the application folder without proper validation. This could allow an attacker to execute arbitrary code with administrative privileges by placing a malicious executable in the same directory.


CVE-2025-29999 has been assigned to this vulnerability. A CVSS v3 base score of 6.7 has been assigned; the CVSS vector string is (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).


A CVSS v4 score has also been calculated for CVE-2025-29999. A base score of 5.4 has been calculated; the CVSS vector string is (AV:L/AC:H/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N).


3.2.2 IMPROPER CERTIFICATE VALIDATION CWE-295


The affected application does not properly restrict permissions of the users. This could allow a lowly-privileged attacker to escalate their privileges.


CVE-2025-30000 has been assigned to this vulnerability. A CVSS v3 base score of 6.7 has been assigned; the CVSS vector string is (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).


A CVSS v4 score has also been calculated for CVE-2025-30000. A base score of 5.4 has been calculated; the CVSS vector string is (AV:L/AC:H/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N).


3.3 BACKGROUND



  • CRITICAL INFRASTRUCTURE SECTORS: Chemical, Critical Manufacturing, Energy, Food and Agriculture, Water and Wastewater Systems

  • COUNTRIES/AREAS DEPLOYED: Worldwide

  • COMPANY HEADQUARTERS LOCATION: Germany


3.4 RESEARCHER


Intel PSIRT reported these vulnerabilities to Siemens.


4. MITIGATIONS


Siemens has released a new version for Siemens License Server (SLS)
and recommends updating to the latest version:



As a general security measure, Siemens recommends protecting network access to devices with appropriate mechanisms. To operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens' operational guidelines for industrial security and following recommendations in the product manuals.


Additional information on industrial security by Siemens can be found on the Siemens industrial security webpage


For more information see the associated Siemens security advisory SSA-525431 in HTML and CSAF.


CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as:



  • Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.

  • Locate control system networks and remote devices behind firewalls and isolating them from business networks.

  • When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs). Recognize VPNs may have vulnerabilities, should be updated to the most recent version available, and are only as secure as the connected devices.


CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.


CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.


CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.


Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.


Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.


No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities are not exploitable remotely. These vulnerabilities have a high attack complexity.


5. UPDATE HISTORY



  • April 10, 2025: Initial Publication


 

Cyber Threat Intelligence & Forensik

ATT&CK-Navigator · IoC-Radar · Exploit-Belege
IoC Intelligence
2 Indikatoren · Defanged · STIX 2.1
CVE-2025-29999CVE-2025-30000
CTI Threat Relationship Graph
Akteure · Techniken · Beziehungen
2 Knoten · 1 Relationen
CVE / Incident Threat Actor Software MITRE ATT&CK CWE Weakness IoC
Exploit & Remediation Lifecycle
PoC · Ausnutzung · Patch-Stufen
CVE-2025-29999
Entdeckung & Meldung
Schwachstelle identifiziert & registriert
Sicherheits-Advisory
Offizielle Warnung & CVE-Zuweisung
Exploit / PoC
Bislang kein öffentlicher Exploit
In-the-Wild Ausnutzung
Keine Massenausnutzung gemeldet
Patch & Schutzmaßnahmen
Noch kein offizieller Patch dokumentiert
Exploit Weaponization & PoC Radar
Nur belegte Faktoren · kein Score-Theater
LOW · Index 0/100
Exploit-DB
Kein EDB-Eintrag
Interaktion
Interaktion nötig
Authentifizierung
Erforderlich

Compliance, SLA & Vendor Adherence

Advisory-Prüfung · Score-Einordnung · Fristen
CVSS 6.7CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Impact: 5.87 | Exploitability: 0.76
AVL
Lokal (Dateisystem / SSH)
Erfordert bereits ein lokales Benutzerkonto oder Ausführung vor Ort.
ACH
Hoch (High)
Erfordert Vorwissen, spezifische Zeitfenster oder unzuverlässige Race Conditions.
PRL
Niedrig (Standard-Benutzer)
Erfordert Anmeldedaten eines regulären Benutzers.
UIR
Erforderlich (Click/Phishing)
Ein Opfer muss eine präparierte Datei öffnen oder einen Link anklicken.
SU
Unverändert (Scope Unchanged)
Auswirkungen verbleiben isoliert in der angreifbaren Anwendungskomponente.
CH
Hoch (Totaler Abfluss)
Vollständiger Zugriff auf alle sensiblen Datenbank- und Speicherinhalte.
IH
Hoch (Volle Manipulation)
Vollständige Modifikation von Dateien, Parametern oder Ausführung von Code.
AH
Hoch (Totaler Ausfall / DoS)
Dienst oder Server wird komplett unbrauchbar (Denial of Service).
CISA-SSVC-Triage (vulnrichment)CVE-2025-29999
Exploitation: none (Keine bekannte Ausnutzung)Automatable: no (Nicht automatisierbar)Technical Impact: total (Vollständig)
Quelle: CISA-ADP vulnrichment · Stand 2025-04-08T13:25:44.643425Z · CISA Coordinator
Advisory Radar

Hersteller-Sicherheitsmeldungen & Patch-Status

In herstellerseitiger Prüfung
Handlungsempfehlung für Administratoren

Hersteller-Advisory noch nicht formal hinterlegt. Regelmäßiges Re-Scanning der CTI-Quellen anberaumt.

Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Siemens License Server

Thematisch verwandte Begriffe: Siemens, License, Server · 6 Treffer

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
Nächster Beitrag