IM
IronMonkey Threat Research
‹ Back to ICS Advisories

SSA-077553: Multiple Vulnerabilities in Siemens License Server (SLS)

HIGH
CVSS 7.5
Date 2026-08-11T00:00:00+00:00
Source siemens-productcert
Published by Siemens ProductCERT

// Description

Siemens License Server is affected by multiple vulnerabilities which could allow an attacker to elevate its privileges and read arbitrary files on the system. Siemens has released a new version for Siemens License Server (SLS) and recommends to update to the latest version.

// Vulnerabilities (2)

CVE ID CVSS Score Severity Description
CVE-2026-69108 6.0 medium
CVE-2026-69108. The affected application is vulnerable to a local privilege escalation due to an insecure sudoers policy. This could allow an attacker to execute arbitrary commands and plant malicious files as root, leading to full system compromise.
CVE-2026-69109 7.5 high
CVE-2026-69109. The affected application is vulnerable to a path traversal vulnerability due to lack of sanitization of user input. This could allow a remote attacker to access arbitrary files on the application.

// Remediations (1)

Patch: Update to V5.3 or later version
Update to V5.3 or later version

// References