cbcvebase.
CVE-2023-47100
published 2024-11-14

CVE-2023-47100: ICS Advisory ## Siemens SINEC INS Release DateNovember 14, 2024 Alert CodeICSA-24-319-08 Related topics: Industrial Control System Vulnerabilities, Industrial…

critical9.8
ICS Advisory


##
Siemens SINEC INS



Release DateNovember 14, 2024



Alert CodeICSA-24-319-08



Related topics:

Industrial Control System Vulnerabilities, Industrial Control Systems

















As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).

View CSAF

## 1. EXECUTIVE SUMMARY

- CVSS v3 9.9

- ATTENTION: Exploitable remotely/low attack complexity/public exploits are available/known public exploitation

- Vendor: Siemens

- Equipment: SINEC INS

- Vulnerabilities: Improper Authentication, Out-of-bounds Write, Inefficient Regular Expression Complexity, Excessive Iteration, Reachable Assertion, Uncontrolled Resource Consumption, Improper Input Validation, Improper Check for Unusual or Exceptional Conditions, Memory Allocation with Excessive Size Value, Heap-based Buffer Overflow, Missing Encryption of Sensitive Data, Path Traversal, Incorrect Permission Assignment for Critical Resource, Exposure of Sensitive Information to an Unauthorized Actor, Covert Timing Channel, Truncation of Security-relevant Information, Integer Overflow or Wraparound, Use After Free, Code Injection, Path Traversal: 'dir/../../filename', Execution with Unnecessary Privileges, Server-Side Request Forgery (SSRF), OS Command Injection, HTTP Request/Response Smuggling, Use of Hard-coded Cryptographic Key, Insufficient Session Expiration

## 2. RISK EVALUATION

Successful exploitation of this vulnerability could allow an unauthenticated attacker cause a denial-of-service condition, bypass permissions, access data they shouldn't have access to, or run arbitrary code.

## 3. TECHNICAL DETAILS

## 3.1 AFFECTED PRODUCTS

The following Siemens products are affected:

- SINEC INS: versions prior to V1.0 SP2 Update 3

## 3.2 Vulnerab

Affected

3 ranges
VendorProductVersion rangeFixed in
applemacos_sequoia
msrccbl2_perl_5.34.1-489_on_cbl_mariner_2.0
msrccbl2_perl_5.34.1-490_on_cbl_mariner_2.0

CVSS provenance

vendor_msrc9.8CRITICAL
vendor_oracle9.8HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.