LOW🇬🇧 English

CVE-2023-28829

CVSS 3.9v3.1pub. 2023-06-13upd. 2024-11-21

Zidentyfikowano podatność w SIMATIC NET PC Software V14 (wszystkie wersje), SIMATIC NET PC Software V15 (wszystkie wersje), SIMATIC PCS 7 V8.2 (wszystkie wersje), SIMATIC PCS 7 V9.0 (wszystkie wersje), SIMATIC PCS 7 V9.1 (wszystkie wersje), SIMATIC WinCC (wszystkie wersje < V8.0), SINAUT Software ST7sc (wszystkie wersje). Przed SIMATIC WinCC V8 starsze usługi OPC (OPC DA, OPC HDA i OPC AE) były domyślnie używane. Usługi te zostały zbudowane na mechanizmach Windows ActiveX i DCOM i nie implementują nowoczesnych mechanizmów bezpieczeństwa do uwierzytelniania i szyfrowania treści.

Pokaż oryginał (EN)

A vulnerability has been identified in SIMATIC NET PC Software V14 (All versions), SIMATIC NET PC Software V15 (All versions), SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS 7 V9.1 (All versions), SIMATIC WinCC (All versions < V8.0), SINAUT Software ST7sc (All versions). Before SIMATIC WinCC V8, legacy OPC services (OPC DA (Data Access), OPC HDA (Historical Data Access), and OPC AE (Alarms & Events)) were used per default. These services were designed on top of the Windows ActiveX and DCOM mechanisms and do not implement state-of-the-art security mechanisms for authentication and encryption of contents.

CVSS Vector
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L
  • Siemens Simatic Net Pc Software

    APP
    Siemens
    14.015.0
  • Siemens Simatic Pcs 7

    APP
    Siemens
    8.29.09.1
  • Siemens Simatic Wincc

    APP
    Siemens
    < 8.0
  • Siemens Sinaut St7sc

    APP
    Siemens
    wszystkie wersje
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2023-25910CRITICAL10.0PL ✓ten sam produkt

Siemens SIMATIC — RCE przez wbudowane funkcje systemu zarządzania bazą danych

CVE-2021-40358CRITICAL9.9PL ✓ten sam produkt

Path Traversal w SIMATIC PCS 7 i WinCC — nieautoryzowany dostęp do plików

CVE-2019-10922CRITICAL9.8PL ✓ten sam produkt

RCE bez uwierzytelnienia w Siemens SIMATIC PCS 7 i WinCC

CVE-2016-5743CRITICAL9.8PL ✓ten sam produkt

RCE w Siemens SIMATIC WinCC i PCS 7 poprzez spreparowane pakiety sieciowe

CVE-2023-48363HIGH7.1ten sam produkt

A vulnerability has been identified in OpenPCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC BATCH V9.1 (All ...