The vendor explicitly identifies these products as affected by this CVE.
- SIMATIC Energy Manager Basic
- SIMATIC Energy Manager PRO
- Summary
- Affected applications improperly assign permissions to critical directories and files used by the application processes. This could allow a local unprivileged attacker to achieve code execution with ADMINISTRATOR or even NT AUTHORITY/SYSTEM privileges.
- Remediation
- Update to V7.3 Update 1 or later version
