Information disclosure in Siemens products - CVE-2023-23588
Published: April 12, 2023
Vulnerability identifier: #VU75035
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-23588
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application in the Adaptec Maxview application. A local attacker can decrypt intercepted local traffic between the browser and the application.
Affected software
SIMATIC IPC647D
SIMATIC IPC847D
SIMATIC IPC1047
SIMATIC IPC647E
SIMATIC IPC847E
SIMATIC IPC1047E
SIMATIC IPC847D
SIMATIC IPC1047
SIMATIC IPC647E
SIMATIC IPC847E
SIMATIC IPC1047E
How to mitigate CVE-2023-23588
Install updates from vendor's website.
SIMATIC IPC647E - update to 4.09.00.25611
SIMATIC IPC847E - update to 4.09.00.25611
SIMATIC IPC1047E - update to 4.09.00.25611
SIMATIC IPC847E - update to 4.09.00.25611
SIMATIC IPC1047E - update to 4.09.00.25611