#VU74816 External Control of File Name or Path in TIA Portal - CVE-2023-26293
Published: April 11, 2023
TIA Portal
Siemens
Description
The vulnerability allows a remote attacker to create or overwrite arbitrary files.
The vulnerability exists due to improper input validation of path names inside PC system configuration files. A remote attacker can trick the victim to open a specially crafted PC system configuration file and create or overwrite arbitrary files on the system.