High severity7.8NVD Advisory· Published Nov 9, 2021· Updated Jun 17, 2026
CVE-2021-37207
CVE-2021-37207
Description
A vulnerability has been identified in SENTRON powermanager V3 (All versions). The affected application assigns improper access rights to a specific folder containing configuration files. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges.
Affected products
4- cpe:2.3:a:siemens:sentron_powermanager_3:*:*:*:*:*:*:*:*Range: >=3.0,<=3.6
- Range: All versions
All versions+ 1 more
- (no CPE)range: All versions
- (no CPE)range: All versions
Patches
Vulnerability mechanics
References
1- cert-portal.siemens.com/productcert/pdf/ssa-537983.pdfnvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.