Information disclosure in Siemens products - CVE-2023-23588

 

Information disclosure in Siemens products - CVE-2023-23588

Published: April 12, 2023


Vulnerability identifier: #VU75035
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-23588
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application in the Adaptec Maxview application. A local attacker can decrypt intercepted local traffic between the browser and the application.


Affected software

SIMATIC IPC647D
SIMATIC IPC847D
SIMATIC IPC1047
SIMATIC IPC647E
SIMATIC IPC847E
SIMATIC IPC1047E

How to mitigate CVE-2023-23588

Install updates from vendor's website.

SIMATIC IPC647E - update to 4.09.00.25611
SIMATIC IPC847E - update to 4.09.00.25611
SIMATIC IPC1047E - update to 4.09.00.25611

External References

Related Security Bulletins