Privilege Escalation Vulnerabilities in Siemens License Server Before V4.3
Monitor6.7SSA-525431Apr 8, 2025
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionRequired
Summary
Siemens License Server before V4.3 contains privilege escalation vulnerabilities (CWE-269, CWE-295) that allow a low-privileged local user to escalate privileges or execute arbitrary code through a combination of improper access control and certificate validation flaws. The vulnerabilities require user interaction or ability to introduce a malicious file on the License Server machine.
What this means
What could happen
A low-privileged user on a machine running Siemens License Server could escalate their privileges or execute arbitrary code, potentially gaining control over license distribution and authorization services that protect Siemens engineering tools used in industrial automation environments.
Who's at risk
Organizations running Siemens License Server (SLS) to manage licenses for Siemens automation engineering tools (such as TIA Portal, Step 7, or PLCSIM). This affects companies using Siemens PLCs, HMIs, or SCADA systems in manufacturing, water treatment, power distribution, or other industrial environments. License servers are often centralized infrastructure shared across engineering departments.
How it could be exploited
An attacker with a local user account on the License Server machine would need to interact with the vulnerable License Server process (likely through a malicious file or UI interaction). The vulnerability combines improper access control (CWE-269) and certificate validation issues (CWE-295) to allow privilege escalation to system or service account level, from which they could modify license data or execute commands affecting dependent automation systems.
Prerequisites
- Local user account on the License Server machine
- User interaction or ability to place a malicious file on the system
- License Server version prior to 4.3 installed and running
Local privilege escalationCertificate validation bypassRequires local access to License Server machineMedium CVSS score (6.7)
Exploitability
Low exploit probability (EPSS 0.1%)
Affected products (1)
ProductAffected VersionsFix Status
License Server (SLS)< V4.34.3
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXUpdate Siemens License Server to version 4.3 or later
CVEs (2)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/a8f13864-7378-44b2-8b5c-a2271d6f7e8c