CVE-2023-48364
published 2024-02-13CVE-2023-48364: A vulnerability has been identified in OpenPCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 UC05), SIMATIC PCS 7 V9.1…
PriorityP427medium6.5CVSS 3.1
AVAACLPRNUINSUCNINAH
EPSS
0.27%
18.8th percentile
A vulnerability has been identified in OpenPCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 UC05), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC Route Control V9.1 (All versions < V9.1 SP2 UC05), SIMATIC WinCC Runtime Professional V18 (All versions < V18 Update 4), SIMATIC WinCC Runtime Professional V19 (All versions < V19 Update 2), SIMATIC WinCC V7.4 (All versions), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 15), SIMATIC WinCC V8.0 (All versions < V8.0 Update 4). The implementation of the RPC (Remote Procedure call) communication protocol in the affected products do not properly handle certain malformed RPC messages. An attacker could use this vulnerability to cause a denial of service condition in the RPC server.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | openpcs_7 | <= 9.1 | — |
| siemens | openpcs_7_v9.1 | — | — |
| siemens | simatic_batch | <= 9.1 | — |
| siemens | simatic_batch_v9.1 | — | — |
| siemens | simatic_pcs_7 | <= 9.1 | — |
| siemens | simatic_pcs_7_v9.1 | < V9.1 SP2 UC05 | V9.1 SP2 UC05 |
| siemens | simatic_route_control | <= 9.1 | — |
| siemens | simatic_route_control_v9.1 | — | — |
| siemens | simatic_wincc | — | — |
| siemens | simatic_wincc | — | — |
| siemens | simatic_wincc | — | — |
| siemens | simatic_wincc_runtime_professional | <= 18 | — |
| siemens | simatic_wincc_runtime_professional | — | — |
| siemens | simatic_wincc_runtime_professional_v18 | < V18 Update 4 | V18 Update 4 |
| siemens | simatic_wincc_runtime_professional_v19 | < V19 Update 2 | V19 Update 2 |
| siemens | simatic_wincc_v7.4 | < * | * |
| siemens | simatic_wincc_v7.5 | < V7.5 SP2 Update 15 | V7.5 SP2 Update 15 |
| siemens | simatic_wincc_v8.0 | < V8.0 Update 4 | V8.0 Update 4 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.07.1HIGHCVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC WinCC, OpenPCS
cisa_ics·2024-02-15·CVSS 7.1
[HIGH] Siemens SIMATIC WinCC, OpenPCS
ICS Advisory
##
Siemens SIMATIC WinCC, OpenPCS
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-12
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 7.1
- ATTENTION: Exploitable from adjacent network/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC, OpenPCS
- Vulnerabilities: NULL Pointer Dereference
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to cause a persistent denial-of-service cond
GHSA
GHSA-m3wg-jr4x-9483: A vulnerability has been identified in OpenPCS 7 V9
ghsa_unreviewed·2024-02-13
CVE-2023-48364 [HIGH] CWE-476 GHSA-m3wg-jr4x-9483: A vulnerability has been identified in OpenPCS 7 V9
A vulnerability has been identified in OpenPCS 7 V9.1 (All versions), SIMATIC BATCH V9.1 (All versions), SIMATIC PCS 7 V9.1 (All versions), SIMATIC Route Control V9.1 (All versions), SIMATIC WinCC Runtime Professional V18 (All versions), SIMATIC WinCC Runtime Professional V19 (All versions), SIMATIC WinCC V7.4 (All versions), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 15), SIMATIC WinCC V8.0 (All versions < V8.0 SP4). The implementation of the RPC (Remote Procedure call) communication protocol in the affected products do not properly handle certain malformed RPC messages. An attacker could use this vulnerability to cause a denial of service condition in the RPC server.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-02-13
Published