High severity7.8NVD Advisory· Published Jun 14, 2022· Updated Jun 17, 2026
CVE-2022-31465
CVE-2022-31465
Description
A vulnerability has been identified in Xpedition Designer VX.2.10 (All versions < VX.2.10 Update 13), Xpedition Designer VX.2.11 (All versions < VX.2.11 Update 11), Xpedition Designer VX.2.12 (All versions < VX.2.12 Update 5), Xpedition Designer VX.2.13 (All versions < VX.2.13 Update 1). The affected application assigns improper access rights to the service executable. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges.
Affected products
6cpe:2.3:a:siemens:xpedition_designer:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:siemens:xpedition_designer:*:*:*:*:*:*:*:*range: <vx.2.11
- (no CPE)range: All versions < VX.2.10 Update 13
- (no CPE)range: All versions < VX.2.11 Update 11
- (no CPE)range: All versions < VX.2.12 Update 5
- (no CPE)range: All versions < VX.2.13 Update 1
Patches
Vulnerability mechanics
References
1- cert-portal.siemens.com/productcert/pdf/ssa-988345.pdfnvdVendor Advisory
News mentions
0No linked articles in our index yet.