Overly permissive cross-domain whitelist in SIMATIC PCS neo - CVE-2023-46098

 

Overly permissive cross-domain whitelist in SIMATIC PCS neo - CVE-2023-46098

Published: November 15, 2023


Vulnerability identifier: #VU83179
CSH Severity: Medium
CVSS v4: 8.5 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-46098
CWE-ID: CWE-942
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass the CORS protection mechanism.

The vulnerability exists due to incorrect processing of the "Origin" HTTP header that is supplied within HTTP request when accessing the Information Server. A remote attacker on the local network can trick a victim to trigger unwanted behavior


Affected software

SIMATIC PCS neo

How to mitigate CVE-2023-46098

Install updates from vendor's website.

SIMATIC PCS neo - update to 4.1

External References

Related Security Bulletins