CVE-2023-46280
published 2024-05-14CVE-2023-46280: A vulnerability has been identified in Security Configuration Tool (SCT) (All versions), SIMATIC Automation Tool (All versions < V5.0 SP2), SIMATIC BATCH V9.1…
PriorityP427medium6.5CVSS 3.1
AVLACLPRLUINSCCNINAH
EPSS
0.26%
17.4th percentile
A vulnerability has been identified in Security Configuration Tool (SCT) (All versions), SIMATIC Automation Tool (All versions < V5.0 SP2), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 Upd5), SIMATIC NET PC Software V16 (All versions < V16 Update 8), SIMATIC NET PC Software V17 (All versions), SIMATIC NET PC Software V18 (All versions < V18 SP1), SIMATIC NET PC Software V19 (All versions < V19 Update 2), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC PDM V9.2 (All versions < V9.2 SP2 Upd3), SIMATIC Route Control V9.1 (All versions < V9.1 SP2 Upd3), SIMATIC S7-PCT (All versions < V3.5 SP3 Update 6), SIMATIC STEP 7 V5 (All versions < V5.7 SP3), SIMATIC WinCC OA V3.17 (All versions), SIMATIC WinCC OA V3.18 (All versions < V3.18 P025), SIMATIC WinCC OA V3.19 (All versions < V3.19 P010), SIMATIC WinCC Runtime Advanced (All versions < V17 Update 8), SIMATIC WinCC Runtime Professional V16 (All versions < V16 Update 6), SIMATIC WinCC Runtime Professional V17 (All versions < V17 Update 8), SIMATIC WinCC Runtime Professional V18 (All versions < V18 Update 4), SIMATIC WinCC Runtime Professional V19 (All versions < V19 Update 2), SIMATIC WinCC V7.4 (All versions), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 17), SIMATIC WinCC V8.0 (All versions < V8.0 Update 5), SINAMICS Startdrive (All versions < V19 SP1), SINEC NMS (All versions < V3.0), SINUMERIK ONE virtual (All versions < V6.23), SINUMERIK PLC Programming Tool (All versions < V3.3.12), TIA Portal Cloud Connector (All versions < V2.0), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions < V17 Update 8), Totally Integrated Automation Portal (TIA Portal) V18 (All versions < V18 Update 4), Totally Integrated Automation Portal (TIA Portal) V19 (All versions < V19 Update 2), SINEC NMS (All versions < V3.0 SP1). The affected applications contain an out of b
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | security_configuration_tool | < * | * |
| siemens | simatic_automation_tool | < V5.0 SP2 | V5.0 SP2 |
| siemens | simatic_batch_v9.1 | < V9.1 SP2 Upd5 | V9.1 SP2 Upd5 |
| siemens | simatic_net_pc_software_v16 | < V16 Update 8 | V16 Update 8 |
| siemens | simatic_net_pc_software_v17 | < * | * |
| siemens | simatic_net_pc_software_v18 | < V18 SP1 | V18 SP1 |
| siemens | simatic_net_pc_software_v19 | < V19 Update 2 | V19 Update 2 |
| siemens | simatic_pcs_7_v9.1 | < V9.1 SP2 UC05 | V9.1 SP2 UC05 |
| siemens | simatic_pdm_v9.2 | < V9.2 SP2 Upd3 | V9.2 SP2 Upd3 |
| siemens | simatic_route_control_v9.1 | < V9.1 SP2 Upd3 | V9.1 SP2 Upd3 |
| siemens | simatic_s7-pct | < V3.5 SP3 Update 6 | V3.5 SP3 Update 6 |
| siemens | simatic_step_7_v5 | < V5.7 SP3 | V5.7 SP3 |
| siemens | simatic_wincc_oa_v3.17 | < * | * |
| siemens | simatic_wincc_oa_v3.18 | < V3.18 P025 | V3.18 P025 |
| siemens | simatic_wincc_oa_v3.19 | < V3.19 P010 | V3.19 P010 |
| siemens | simatic_wincc_runtime_advanced | < V17 Update 8 | V17 Update 8 |
| siemens | simatic_wincc_runtime_professional_v16 | < V16 Update 6 | V16 Update 6 |
| siemens | simatic_wincc_runtime_professional_v17 | < V17 Update 8 | V17 Update 8 |
| siemens | simatic_wincc_runtime_professional_v18 | < V18 Update 4 | V18 Update 4 |
| siemens | simatic_wincc_runtime_professional_v19 | < V19 Update 2 | V19 Update 2 |
| siemens | simatic_wincc_v7.4 | < * | * |
| siemens | simatic_wincc_v7.5 | < V7.5 SP2 Update 17 | V7.5 SP2 Update 17 |
| siemens | simatic_wincc_v8.0 | < V8.0 Update 5 | V8.0 Update 5 |
| siemens | sinamics_startdrive | < V19 SP1 | V19 SP1 |
| siemens | sinec_nms | < V3.0 | V3.0 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
nvdv4.08.2HIGHCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SINEC NMS
cisa_ics·2024-11-14
Siemens SINEC NMS
ICS Advisory
##
Siemens SINEC NMS
Release DateNovember 14, 2024
Alert CodeICSA-24-319-04
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.3
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC NMS
- Vulnerabilities: Improper Input Validation, Improper Check for Unusual or Exceptional Conditions, Out-of-bounds Write, Uncontro
CISA ICS
Siemens SINEC NMS
cisa_ics·2024-08-15·CVSS 7.0
[HIGH] Siemens SINEC NMS
ICS Advisory
##
Siemens SINEC NMS
Release DateAugust 15, 2024
Alert CodeICSA-24-228-06
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 9.4
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC NMS
- Vulnerabilities: Use After Free, Improper Input Validation, Deserialization of Untrusted Data, Improper Restriction of Operations
CISA ICS
Siemens Industrial Products
cisa_ics·2024-05-16
Siemens Industrial Products
ICS Advisory
##
Siemens Industrial Products
Release DateMay 16, 2024
Alert CodeICSA-24-137-13
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.2
- ATTENTION: Low Attack Complexity
- Vendor: Siemens
- Equipment: S7-PCT, SCT, SIMATIC, SINAMICS, SINUMERIK, and TIA Portal Products
- Vulnerability: Out-of-bounds Read
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to cause a Blue Screen of Death (BSOD) crash of
GHSA
GHSA-g3gv-9xvr-p3r6: A vulnerability has been identified in S7-PCT (All versions), Security Configuration Tool (SCT) (All versions), SIMATIC Automation Tool (All versions)
ghsa_unreviewed·2024-05-14
CVE-2023-46280 [HIGH] CWE-125 GHSA-g3gv-9xvr-p3r6: A vulnerability has been identified in S7-PCT (All versions), Security Configuration Tool (SCT) (All versions), SIMATIC Automation Tool (All versions)
A vulnerability has been identified in S7-PCT (All versions), Security Configuration Tool (SCT) (All versions), SIMATIC Automation Tool (All versions), SIMATIC BATCH V9.1 (All versions), SIMATIC NET PC Software (All versions), SIMATIC PCS 7 V9.1 (All versions), SIMATIC PDM V9.2 (All versions), SIMATIC Route Control V9.1 (All versions), SIMATIC STEP 7 V5 (All versions), SIMATIC WinCC OA V3.17 (All versions), SIMATIC WinCC OA V3.18 (All versions < V3.18 P025), SIMATIC WinCC OA V3.19 (All versions < V3.19 P010), SIMATIC WinCC Runtime Advanced (All versions), SIMATIC WinCC Runtime Professional V16 (All versions), SIMATIC WinCC Runtime Professional V17 (All versions), SIMATIC WinCC Runtime Professional V18 (All versions), SIMATIC WinCC Runtime Professional V19 (All versions), SIMATIC WinCC Unif
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-05-14
Published