SB2023061512 - Protection Mechanism Failure in Siemens TIA Portal
Published: June 15, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Protection Mechanism Failure (CVE-ID: CVE-2023-30757)
The vulnerability allows a local attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient implementation of security measures in the know-how protection feature. A local attacker can recover previous, yet unprotected, versions of the project without the knowledge of the know-how protection password.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.