Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject code or spawn a system root shell.
https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-12
https://cert-portal.siemens.com/productcert/pdf/ssa-710008.pdf