Headline
CVE-2022-31465
A vulnerability has been identified in Xpedition Designer (All versions < VX.2.11). The affected application assigns improper access rights to the service executable. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges.
%PDF-1.5 %���� 1 0 obj << /D [2 0 R /XYZ 70.866 771.024 null] >> endobj 3 0 obj << /D [2 0 R /XYZ 70.866 630.026 null] >> endobj 4 0 obj << /D [2 0 R /XYZ 70.866 572.158 null] >> endobj 5 0 obj << /D [2 0 R /XYZ 70.866 421.393 null] >> endobj 6 0 obj << /D [2 0 R /XYZ 70.866 284.601 null] >> endobj 7 0 obj << /D [8 0 R /XYZ 85.039 503.27 null] >> endobj 9 0 obj << /D [8 0 R /XYZ 70.866 315.833 null] >> endobj 10 0 obj << /S /GoTo /D [2 0 R /Fit] >> endobj 2 0 obj << /Contents 11 0 R /Type /Page /Resources 12 0 R /Parent 13 0 R /Annots [14 0 R 15 0 R 16 0 R 17 0 R 18 0 R 19 0 R 20 0 R 21 0 R] /MediaBox [0 0 595.276 841.89] >> endobj 14 0 obj << /A << /S /URI /Type /Action /URI (https://support.sw.siemens.com/en-US/product/852852130/download/202201059/) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 470.704 518.276 482.121] >> endobj 16 0 obj << /A << /S /GoTo /D (section*.3) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [302.649 433.349 433.497 446.026] >> endobj 17 0 obj << /A << /S /GoTo /D (section*.2) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [386.143 301.418 524.579 312.955] >> endobj 18 0 obj << /A << /S /GoTo /D (section*.4) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [147.498 283.605 309.548 295.022] >> endobj 19 0 obj << /A << /S /URI /Type /Action /URI (https://www.siemens.com/cert/operational-guidelines-industrial-security) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [164.798 192.529 487.754 204.066] >> endobj 20 0 obj << /A << /S /URI /Type /Action /URI (https://www.siemens.com/industrialsecurity) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [406.699 162.761 525.406 174.178] >> endobj 12 0 obj << /ProcSet [/PDF /Text] /Font << /F52 22 0 R /F49 23 0 R >> >> endobj 11 0 obj << /Filter /FlateDecode /Length 2648 >> stream xڵZms�H��_��CUfޙ�}�:Nλq����ne�X��^P|��{f@��LJ{U� LOwO��O7��z�.~Z\\���Ӂ�Tz�O�A$���Q�"���,]��r2�*���r_L�D�Y�_;4K�g�Y軡���w�*��~Y]]�M���������.(z䠀#�r}����K���^0yO�͵�gp�{�_�Ψ�ڑ��)!�0��dF<Њ7"��4W�� �"#��l���q���AD���1�p5��DH���12�4!�@a�D]�o�q�\w�@�z�� tW��P\�1"D(p� �Q� UW�OE�=��e�FH(��2B�@�[Lj�O´ ]#�K�ʶ��0���90���G0q�&��y"C�o�"��� �� ��1�sP9� DJ�2��~0e�G���B���!h��%B*N*.�z��m�&�p�����u.N��@:�8 (�v�7i��`���}��ЛRaBўݽ�y���orě�J_C6�8���4�S�Q:N��B8؊��ι�%v��s�¬�}Q�7��$�(JXfs�3 ��y��s;�;���).S���PR�*��n�d4�L�B �m B�%ҭm�rKX�������D���x��`S��SIx@<]�왳�� i}�aX�0�Qf���7��}���8Ϸ�O���M��*^���yOY��}o��9�a�=M��%,Qo\��W��� �MJR��ք�ף��Ě��&ك#*գ��2�d�{�t#)����?@���{o����k�����ʝ�U\;.͍�’��ѵ�DK�2`@WkԄ��j}�T:�cs���pL��%\��d��� ���Ú�ڛ �MյupS���VM�j��=�vLע#RZ G����P� �Y{���!����x�Ah�F�����fo�^_-��p7��x�Y�(�C� N;��"$�BN)��07w��t�������b>`��t�g���l� 1J�I@�T��|O)$����u���Ga\������7?�,�`� ��+k-;Ued@��GX!B�Z�/G C֥����(�Xy���NyE����28N)�=�\��C�H�=ܪ<��H���#�qg���e��� �vSC���3f>L]�G)"J+ȼ���|a�\���3�z��?Ɏ bT[�q�E�Pi�a�D�2��d�/X"������mi�����>[���Iy��m ��߇�������.?��#Q�t���t1�[��C�C�ﰻ�����u�n1�Z+K�)��]<3�i���S� ���W�e3�o�cU��ח��~�3�"�A�l�i"���� �q�n�@Ƶ?��َ�e�D4�@҄2�. �^&�|n�m�\b1�P�ˎ�u�:�"��<?�X6�x����# 2��A�?۵}\`�rV�*ԕ��P2B~r��W��[����ݤ�!�-D�ʭ|4�j,��Hz~�’��gɰ�� K�Sy\g`|��{`R�L�j��/3ˤ�?�"RP���Q%��Q5F�%Qձc�F�H��g)�^%c$�f��>�&����fq�n6ѡ�Lj>\�֭�XDq�^1��+��)7U�GRKD]� ����� �C�Y��r�.̈́�����ÜD�9��>��_�N�[#���r_V�5���iK[�����P �����=�V��}i�