jiansiting / CVE-2019-10915

Siemens TIA administrator Tool RCE

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

The vulnerability is an authentication bypass in the TIA Administrator server. An attacker could execute arbitrary application commands through websockets on the node.js server which is externally exposed by default. By exploiting this vulnerability, an unauthenticated remote attacker could perform actions on TIA Portal, such as elevating privileges, changing proxy settings, or specifying malicious firmware updates.

About

Siemens TIA administrator Tool RCE

License:GNU General Public License v3.0


Languages

Language:Python 100.0%