CVE-2023-28832
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: productcert@siemens.com (Secondary)
Description
A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2.0 < V2.1). The web based management of affected devices does not properly validate user input, making it susceptible to command injection. This could allow an authenticated privileged remote attacker to execute arbitrary code with root privileges.
Affected (2)
Products: Siemens: 6gk1411 1ac00 Firmware, 6gk1411 5ac00 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens 6gk1411 1ac00 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens 6gk1411 5ac00 | All versions |
References (2)
Source: productcert@siemens.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.