CVE-2020-10056: Siemens License Management Utility
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
A vulnerability has been identified in License Management Utility (LMU) (All versions < V2.4). The lmgrd service of the affected application is executed with local SYSTEM privileges on the server while its configuration can be modified by local users. The vulnerability could allow a local authenticated attacker to execute arbitrary commands on the server with local SYSTEM privileges.
Affected products
- Siemens License Management Utility: before 2.4 (fixed in 2.4)
Published 2020-09-09. Last modified 2026-06-17.