CVE-2023-46281Permissive Cross-domain Security Policy with Untrusted Domains in Siemens Opcenter Execution Foundation

Severity
8.8HIGHNVD
CNA7.1
EPSS
0.1%
top 70.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 12

Description

A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo (All versions < V4.1), SINEC NMS (All versions < V2.0 SP1), Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions < V17 Upda

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Patches

🔴Vulnerability Details

2
GHSA
GHSA-9qvw-gvq6-g569: A vulnerability has been identified in Opcenter Quality (All versions), SIMATIC PCS neo (All versions < V42023-12-12
CVEList
CVE-2023-46281: A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo2023-12-12
CVE-2023-46281 — Siemens vulnerability | cvebase