Siemens License Server (SLS)

Plan PatchCVSS 7.5ICS-CERT ICSA-26-225-07Aug 11, 2026
Siemens
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

Siemens License Server (SLS) contains multiple vulnerabilities (CWE-732: improper permission assignment, CWE-35: path traversal) that allow an unauthenticated remote attacker to escalate privileges and read arbitrary files on the License Server system. Affected versions: SLS < V5.1 and < V5.3. The vulnerabilities do not require authentication and can be exploited over the network.

What this means
What could happen
An attacker could read sensitive files on the License Server and escalate privileges, potentially accessing configuration data, credentials, or other sensitive information stored on the system.
Who's at risk
This affects organizations using Siemens License Server to manage software licenses for Siemens engineering tools (like TIA Portal, Step 7). Engineering departments, plant IT teams managing development environments, and any site with Siemens automation software are impacted.
How it could be exploited
An attacker with network access to the License Server (typically on port 8080) could exploit the privilege escalation and file read vulnerabilities to access arbitrary files on the host system. No credentials are required for exploitation.
Prerequisites
  • Network access to Siemens License Server (default port 8080)
  • No authentication required
remotely exploitableno authentication requiredlow complexityhigh CVSS score (7.5)
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (2)
2 with fix
ProductAffected VersionsFix Status
License Server (SLS) < V5.1< 5.15.1
License Server (SLS) < V5.3< 5.35.3
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDRestrict network access to the License Server port (8080) to only authorized engineering workstations and admin systems using firewall rules
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HOTFIXUpdate Siemens License Server to version 5.1 or later
HOTFIXUpdate Siemens License Server to version 5.3 or later if you are running the V5.3 branch
API: /api/v1/advisories/6a02af1a-af2f-4945-aa56-6fad9a618b33

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.