CVE-2023-47100
published 2024-11-14CVE-2023-47100: ICS Advisory ## Siemens SINEC INS Release DateNovember 14, 2024 Alert CodeICSA-24-319-08 Related topics: Industrial Control System Vulnerabilities, Industrial…
critical9.8
ICS Advisory ## Siemens SINEC INS Release DateNovember 14, 2024 Alert CodeICSA-24-319-08 Related topics: Industrial Control System Vulnerabilities, Industrial Control Systems As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global). View CSAF ## 1. EXECUTIVE SUMMARY - CVSS v3 9.9 - ATTENTION: Exploitable remotely/low attack complexity/public exploits are available/known public exploitation - Vendor: Siemens - Equipment: SINEC INS - Vulnerabilities: Improper Authentication, Out-of-bounds Write, Inefficient Regular Expression Complexity, Excessive Iteration, Reachable Assertion, Uncontrolled Resource Consumption, Improper Input Validation, Improper Check for Unusual or Exceptional Conditions, Memory Allocation with Excessive Size Value, Heap-based Buffer Overflow, Missing Encryption of Sensitive Data, Path Traversal, Incorrect Permission Assignment for Critical Resource, Exposure of Sensitive Information to an Unauthorized Actor, Covert Timing Channel, Truncation of Security-relevant Information, Integer Overflow or Wraparound, Use After Free, Code Injection, Path Traversal: 'dir/../../filename', Execution with Unnecessary Privileges, Server-Side Request Forgery (SSRF), OS Command Injection, HTTP Request/Response Smuggling, Use of Hard-coded Cryptographic Key, Insufficient Session Expiration ## 2. RISK EVALUATION Successful exploitation of this vulnerability could allow an unauthenticated attacker cause a denial-of-service condition, bypass permissions, access data they shouldn't have access to, or run arbitrary code. ## 3. TECHNICAL DETAILS ## 3.1 AFFECTED PRODUCTS The following Siemens products are affected: - SINEC INS: versions prior to V1.0 SP2 Update 3 ## 3.2 Vulnerab
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos_sequoia | — | — |
| msrc | cbl2_perl_5.34.1-489_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_perl_5.34.1-490_on_cbl_mariner_2.0 | — | — |
CVSS provenance
vendor_msrc9.8CRITICAL
vendor_oracle9.8HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2023-47100: macOS Sequoia 15.2
vendor_apple·2024-12-11·CVSS 7.0
CVE-2023-47100 [HIGH] CVE-2023-47100: macOS Sequoia 15.2
Apple Security Update: About the security content of macOS Sequoia 15.2
Product: macOS Sequoia
Version: 15.2
CVE: CVE-2023-47100
Component: CVE-2023-47100
CISA ICS
Siemens SINEC INS
cisa_ics·2024-11-14
Siemens SINEC INS
ICS Advisory
##
Siemens SINEC INS
Release DateNovember 14, 2024
Alert CodeICSA-24-319-08
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.9
- ATTENTION: Exploitable remotely/low attack complexity/public exploits are available/known public exploitation
- Vendor: Siemens
- Equipment: SINEC INS
- Vulnerabilities: Improper Authentication, Out-of-bounds Write, Ineffici
Oracle
Oracle Oracle Communications Applications Risk Matrix: Platform (Perl) — CVE-2023-47100
vendor_oracle·2024-04-15·CVSS 9.8
CVE-2023-47100 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Platform (Perl) — CVE-2023-47100
Oracle Oracle Communications Applications Risk Matrix: Platform (Perl) vulnerability
CVE: CVE-2023-47100
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2024 (APR 2024)
Microsoft
In Perl before 5.38.2, S_parse_uniprop_string in regcomp.c can write to unallocated space because a property name associated with a \p{...} regular expression construct is mishandled. The earliest aff
vendor_msrc·2023-12-12·CVSS 9.8
CVE-2023-47100 [HIGH] CWE-755 In Perl before 5.38.2, S_parse_uniprop_string in regcomp.c can write to unallocated space because a property name associated with a \p{...} regular expression construct is mishandled. The earliest aff
In Perl before 5.38.2, S_parse_uniprop_string in regcomp.c can write to unallocated space because a property name associated with a \p{...} regular expression construct is mishandled. The earliest affected version is 5.30.0.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identi
Red Hat
perl: Perl security bypass
vendor_redhat·2023-12-03·CVSS 7.0
CVE-2023-47100 [HIGH] CWE-755 perl: Perl security bypass
perl: Perl security bypass
A flaw was found in Perl due to improper handling of the property name by the S_parse_uniprop_string function in regcomp.c. This issue could allow an attacker to to bypass security restrictions and use a specially crafted regular expression input to write to unallocated space.
Statement: This flaw was found to be a duplicate of CVE-2023-47038. Please see https://access.redhat.com/security/cve/CVE-2023-47038 for information about affected products and security errata.
Package: perl (Red Hat Enterprise Linux 6) - Not affected
Package: perl (Red Hat Enterprise Linux 7) - Not affected
Package: perl (Red Hat Enterprise Linux 8) - Not affected
Package: perl:5.32/perl (Red Hat Enterprise Linux 8) - Not affected
Package: perl (Red Hat Enterprise Linux 9) - Not aff
GHSA
GHSA-hx28-vm67-xh3r: In Perl before 5
ghsa_unreviewed·2023-12-03
CVE-2023-47100 [CRITICAL] CWE-755 GHSA-hx28-vm67-xh3r: In Perl before 5
In Perl before 5.38.2, S_parse_uniprop_string in regcomp.c can write to unallocated space because a property name associated with a \p{...} regular expression construct is mishandled. The earliest affected version is 5.30.0.
No detection rules found.
No public exploits indexed.
Qualys
Oracle Security Updates, April 2024: Critical Patch | Qualys
blogs_qualys·2024-04-17
Oracle Security Updates, April 2024: Critical Patch | Qualys
#### Table of Contents
- Qualys QID Coverage
- Notable Oracle Vulnerabilities Patched
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
Oracle released its second quarterly edition of Critical Patch Update, which contains patches for 441 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In the second quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 93, constituting about 21% of the total patches released. Oracle Fusion Middleware and Oracle Financial Services Applicat
Qualys
Oracle Patch Update, April 2024 Security Update Review
blogs_qualys·2024-04-17
Oracle Patch Update, April 2024 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
Oracle released its second quarterly edition of Critical Patch Update, which contains patches for 441 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In the second quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 93, constituting about 21% of the total patches released. Oracle Fusion Middleware and Oracle Financial Services Applications fo
2024-11-14
Published