Siemens License Server Flaws Could Let Attackers Elevate Privileges, Access Files
Siemens has released an updated version of its License Server (SLS) software to fix two security vulnerabilities that could be exploited by attackers to escalate their privileges and access files they shouldn't be able to see. The issues stem from incorrect permission settings and a path traversal flaw, which lets attackers navigate outside of intended directories to reach restricted data.
The vulnerabilities affect versions of Siemens License Server prior to 5.1 and 5.3, and have been rated with a CVSS score of 7.5, indicating a high severity level. While no active exploitation has been reported, the flaws could be leveraged by an attacker who already has some level of network access to expand their reach within an affected system.
Siemens products are widely deployed across industrial and IT environments globally, including in Australia. Any business using Siemens License Server as part of its software licensing infrastructure should treat this update as a priority, particularly given the sensitivity of licensing systems that often interact with core business applications.