CVE-2023-46285
published 2023-12-12CVE-2023-46285: A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo (All…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.91%
55.8th percentile
A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo (All versions < V4.1), SINEC NMS (All versions < V2.0 SP1), Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions < V17 Update 8), Totally Integrated Automation Portal (TIA Portal) V18 (All versions < V18 Update 3). The affected application contains an improper input validation vulnerability that could allow an attacker to bring the service into a Denial-of-Service state by sending a specifically crafted message to 4004/tcp. The corresponding service is auto-restarted after the crash is detected by a watchdog.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | opcenter_execution_foundation | < V2407 | V2407 |
| siemens | opcenter_quality | < V2312 | V2312 |
| siemens | simatic_pcs_neo | < V4.1 | V4.1 |
| siemens | simatic_pcs_neo | < 4.1 | 4.1 |
| siemens | sinec_nms | < V2.0 SP1 | V2.0 SP1 |
| siemens | totally_integrated_automation_portal | — | — |
| siemens | totally_integrated_automation_portal | >= 14.0 < 15 | 15 |
| siemens | totally_integrated_automation_portal | >= 15 < 16 | 16 |
| siemens | totally_integrated_automation_portal | >= 16 < 17 | 17 |
| siemens | totally_integrated_automation_portal | >= 17 < 18 | 18 |
| siemens | totally_integrated_automation_portal_v14 | < * | * |
| siemens | totally_integrated_automation_portal_v15.1 | < * | * |
| siemens | totally_integrated_automation_portal_v16 | < * | * |
| siemens | totally_integrated_automation_portal_v17 | < V17 Update 8 | V17 Update 8 |
| siemens | totally_integrated_automation_portal_v18 | < V18 Update 3 | V18 Update 3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-84mm-xgw8-mv4q: A vulnerability has been identified in Opcenter Quality (All versions), SIMATIC PCS neo (All versions < V4
ghsa_unreviewed·2023-12-12
CVE-2023-46285 [HIGH] CWE-20 GHSA-84mm-xgw8-mv4q: A vulnerability has been identified in Opcenter Quality (All versions), SIMATIC PCS neo (All versions < V4
A vulnerability has been identified in Opcenter Quality (All versions), SIMATIC PCS neo (All versions < V4.1), SINUMERIK Integrate RunMyHMI /Automotive (All versions), Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All versions < V18 Update 3). The affected application contains an improper input validation vulnerability that could allow an attacker to bring the service into a Denial-of-Service state by sending a specifically crafted message to 4004/tcp. The corresponding service is auto-restarted after th
CISA ICS
Siemens User Management Component (UMC)
cisa_ics·2023-12-14·CVSS 7.1
[HIGH] Siemens User Management Component (UMC)
ICS Advisory
##
Siemens User Management Component (UMC)
Release DateDecember 14, 2023
Alert CodeICSA-23-348-03
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: User Management Component (UMC)
- Vulnerabilities: Permissive Cross-domain Policy with Untrusted Domains, Cross-site Scripting, Classic Buffer Overflow, Improper Input Validation
## 2. RISK EVALUATION
Suc
BSD
OpenBSD 7.2 Errata 014: SECURITY FIX
bsd_advisories·2023-01-17·CVSS 7.5
CVE-2022-44617 [HIGH] OpenBSD 7.2 Errata 014: SECURITY FIX
OpenBSD 7.2 Errata 014: SECURITY FIX
014: SECURITY FIX: January 17, 2023
All architectures Input validation issues and path validation issues in libXpm can lead to infinite loops, memory corruption or arbitrary command execution. CVE-2022-46285, CVE-2022-44617 and CVE-2022-4883
BSD
OpenBSD 7.1 Errata 019: SECURITY FIX
bsd_advisories·2023-01-17·CVSS 7.5
CVE-2022-44617 [HIGH] OpenBSD 7.1 Errata 019: SECURITY FIX
OpenBSD 7.1 Errata 019: SECURITY FIX
019: SECURITY FIX: January 17, 2023
All architectures Input validation issues and path validation issues in libXpm can lead to infinite loops, memory corruption or arbitrary command execution. CVE-2022-46285, CVE-2022-44617 and CVE-2022-4883
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-12-12
Published