Executive brief
Siemens License Server (SLS), a central licensing application used by Siemens' EDA and PLM products, contains a privilege escalation flaw in its sudoers configuration. A local attacker with elevated privileges can exploit this to execute arbitrary commands as root and modify system files, potentially compromising the entire server and any systems that depend on it for licensing services.
Technical details
The vulnerability is a privilege escalation flaw stemming from an insecure sudoers policy (CWE-732: Incorrect Permission Assignment for Critical Resource). The vulnerable application permits a high-privileged local user to execute arbitrary commands as root without additional authentication, enabling full system compromise. Attack precondition: local access and high-privilege user context (PR:H). The flaw allows an attacker to execute code and plant malicious files with root privileges. Siemens has released version 5.1 and later to remediate this issue; upgrading is the recommended mitigation.
Affected products
- Siemens License Server (SLS) All versions < 5.1
Timeline
- 2026-08-11: disclosed