Incorrect permission assignment for critical resource in SIMATIC IPC DiagBase and SIMATIC IPC DiagMonitor - CVE-2025-23403
Published: February 12, 2025
Vulnerability identifier: #VU103910
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-23403
CWE-ID: CWE-732
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to compromise the target system.
The vulnerability exists due to the affected device do not properly restrict the user permission for the registry key. A local user can load vulnerable drivers into the system and gain elevated privileges on the system.
Affected software
SIMATIC IPC DiagBase
SIMATIC IPC DiagMonitor
SIMATIC IPC DiagMonitor
How to mitigate CVE-2025-23403
Install updates from vendor's website.