Information disclosure in Siemens products - CVE-2023-27465

 

Information disclosure in Siemens products - CVE-2023-27465

Published: June 14, 2023


Vulnerability identifier: #VU77309
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-27465
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to gain access to potentially sensitive information.

The vulnerability exists due to the affected device does not protect access to certain services relevant for debugging. An attacker with physical access can extract confidential technology object (TO) configuration from the device.


Affected software

SIMOTION C240 PN
SIMOTION P320-4 S
SIMOTION D410-2 DP/PN
SIMOTION D425-2 DP
SIMOTION P320-4 E
SIMOTION D425-2 DP/PN
SIMOTION D435-2 DP
SIMOTION C240
SIMOTION D435-2 DP/PN
SIMOTION D455-2 DP/PN
SIMOTION D445-2 DP/PN

How to mitigate CVE-2023-27465

Install updates from vendor's website.

SIMOTION C240 PN - update to 5.5 SP1
SIMOTION D410-2 DP/PN - update to 5.5 SP1
SIMOTION D425-2 DP - update to 5.5 SP1
SIMOTION D425-2 DP/PN - update to 5.5 SP1
SIMOTION D435-2 DP - update to 5.5 SP1
SIMOTION C240 - update to 5.5 SP1
SIMOTION D435-2 DP/PN - update to 5.5 SP1
SIMOTION D455-2 DP/PN - update to 5.5 SP1
SIMOTION D445-2 DP/PN - update to 5.5 SP1

External References

Related Security Bulletins