Risk | Low |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2023-23588 |
CWE-ID | CWE-200 |
Exploitation vector | Local |
Public exploit | N/A |
Vulnerable software |
SIMATIC IPC647D Server applications / SCADA systems SIMATIC IPC847D Server applications / SCADA systems SIMATIC IPC1047 Hardware solutions / Firmware SIMATIC IPC647E Hardware solutions / Firmware SIMATIC IPC847E Hardware solutions / Firmware SIMATIC IPC1047E Hardware solutions / Firmware |
Vendor | Siemens |
Security Bulletin
This security bulletin contains one low risk vulnerability.
EUVDB-ID: #VU75035
Risk: Low
CVSSv4.0: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2023-23588
CWE-ID:
CWE-200 - Information exposure
Exploit availability: No
DescriptionThe vulnerability allows a local attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application in the Adaptec Maxview application. A local attacker can decrypt intercepted local traffic between the browser and the application.
MitigationInstall updates from vendor's website.
Vulnerable software versionsSIMATIC IPC647D: All versions
SIMATIC IPC847D: All versions
SIMATIC IPC1047: All versions
SIMATIC IPC647E: before 4.09.00.25611
SIMATIC IPC847E: before 4.09.00.25611
SIMATIC IPC1047E: before 4.09.00.25611
CPE2.3https://cert-portal.siemens.com/productcert/pdf/ssa-511182.pdf
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
How the attacker can exploit this vulnerability?
The attacker would have to send a specially crafted request to the affected application in order to exploit this vulnerability.
The attacker would have to login to the system and perform certain actions in order to exploit this vulnerability.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.