cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2024-43781,https://securityvulnerability.io/vulnerability/CVE-2024-43781,Insertion of Sensitive Information into Log File Vulnerability Affects SINUMERIK Systems,"A vulnerability has been identified in SINUMERIK 828D V4 (All versions < V4.95 SP3), SINUMERIK 840D sl V4 (All versions < V4.95 SP3 in connection with using Create MyConfig (CMC) <= V4.8 SP1 HF6), SINUMERIK ONE (All versions < V6.23 in connection with using Create MyConfig (CMC) <= V6.6), SINUMERIK ONE (All versions < V6.15 SP4 in connection with using Create MyConfig (CMC) <= V6.6). Affected systems, that have been provisioned with Create MyConfig (CMC), contain a Insertion of Sensitive Information into Log File vulnerability. This could allow a local authenticated user with low privileges to read sensitive information and thus circumvent access restrictions.",Siemens,"Sinumerik 828d V4,Sinumerik 840d Sl V4,Sinumerik One",5.5,MEDIUM,0.0004299999854993075,false,,false,false,false,,false,false,2024-09-10T09:36:51.143Z,0 CVE-2024-41171,https://securityvulnerability.io/vulnerability/CVE-2024-41171,SINUMERIK Devices Vulnerable to Privilege Escalation Attacks,"A vulnerability has been identified in various Siemens SINUMERIK products where access restrictions to scripts executed with elevated privileges are not properly enforced. This flaw affects devices including SINUMERIK 828D, SINUMERIK 840D sl, and SINUMERIK ONE, allowing an authenticated local attacker to escalate privileges, potentially leading to unauthorized control over the system. The issue exists across all versions of SINUMERIK 828D V4 and 840D sl V4, as well as versions of SINUMERIK ONE prior to V6.24, thus posing risks to operational integrity. For more information, visit the official Siemens CERT portal.",Siemens,"Sinumerik 828d V4,Sinumerik 828d V5,Sinumerik 840d Sl V4,Sinumerik One",8.8,HIGH,0.0004299999854993075,false,,false,false,false,,false,false,2024-09-10T09:36:46.244Z,0