CVE-2023-25910
published 2023-06-13CVE-2023-25910: A vulnerability has been identified in SIMATIC PCS 7 (All versions < V9.1 SP2 UC04), SIMATIC S7-PM (All versions < V5.7 SP1 HF1), SIMATIC S7-PM (All versions <…
PriorityP356high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.00%
59.0th percentile
A vulnerability has been identified in SIMATIC PCS 7 (All versions < V9.1 SP2 UC04), SIMATIC S7-PM (All versions < V5.7 SP1 HF1), SIMATIC S7-PM (All versions < V5.7 SP2 HF1), SIMATIC STEP 7 V5 (All versions < V5.7). The affected product contains a database management system that could allow remote users with low privileges to use embedded functions of the database (local or in a network share) that have impact on the server.
An attacker with network access to the server network could leverage these embedded functions to run code with elevated privileges in the database management system's server.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | simatic_pcs_7 | < V9.1 SP2 UC04 | V9.1 SP2 UC04 |
| siemens | simatic_s7-pm | < V5.7 SP1 HF1 | V5.7 SP1 HF1 |
| siemens | simatic_s7-pm | < V5.7 SP2 HF1 | V5.7 SP2 HF1 |
| siemens | simatic_step_7 | < 5.7 | 5.7 |
| siemens | simatic_step_7_v5 | < V5.7 | V5.7 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5wm3-c83x-cqpq: A vulnerability has been identified in SIMATIC PCS 7 (All versions), SIMATIC S7-PM (All versions), SIMATIC STEP 7 V5 (All versions < V5
ghsa_unreviewed·2023-06-13
CVE-2023-25910 [HIGH] CWE-94 GHSA-5wm3-c83x-cqpq: A vulnerability has been identified in SIMATIC PCS 7 (All versions), SIMATIC S7-PM (All versions), SIMATIC STEP 7 V5 (All versions < V5
A vulnerability has been identified in SIMATIC PCS 7 (All versions), SIMATIC S7-PM (All versions), SIMATIC STEP 7 V5 (All versions < V5.7). The affected product contains a database management system that could allow remote users with low privileges to use embedded functions of the database (local or in a network share) that have impact on the server.
An attacker with network access to the server network could leverage these embedded functions to run code with elevated privileges in the database management system's server.
CISA ICS
Siemens SIMATIC STEP 7 and Derived Products
cisa_ics·2023-06-15·CVSS 10.0
[CRITICAL] Siemens SIMATIC STEP 7 and Derived Products
ICS Advisory
##
Siemens SIMATIC STEP 7 and Derived Products
Release DateJune 15, 2023
Alert CodeICSA-23-166-08
## As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.9
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC PCS 7, SIMATIC S7-PM, SIMATIC STEP 7 V5
- Vulnerability: Improper Control of Generation of Code ('Code Injection')
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow remote us
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-06-13
Published