vendor:
Solid Edge
by:
Juan Vazquez
8,8
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: Solid Edge
Affected Version From: ST4
Affected Version To: ST5
Patch Exists: YES
Related CWE: CVE-2013-3269
CPE: cpe:a:siemens:solid_edge:st4
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows Server 2003 r2 sp2, Microsoft Windows XP sp3, Microsoft Windows 7, Internet Explorer 8
2013
SIEMENS Solid Edge ST4/ST5 WebPartHelper ActiveX Control RFMSsvs!JShellExecuteEx Remote Command Execution
The WebPartHelper ActiveX control in SIEMENS Solid Edge ST4/ST5 is vulnerable to remote command execution due to a ShellExecuteExW() call inside RFMSsvs.dll. By passing an null session share path to the URL argument of the OpenInEditor() method, an attacker can launch an arbitrary executable.
Mitigation:
Siemens has released a patch to address this vulnerability.