CVE Database
/

CVE-2023-32735

Back to search

CVE-2023-32735

Published: Jul 9, 2024

Modified: Aug 27, 2025

PUBLISHED

CVSS v3.1

6.5

MEDIUM

Description

A vulnerability has been identified in SIMATIC STEP 7 Safety V16 (All versions < V16 Update 7), SIMATIC STEP 7 Safety V17 (All versions < V17 Update 7), SIMATIC STEP 7 Safety V18 (All versions < V18 Update 2), SIMATIC STEP 7 V16 (All versions < V16 Update 7), SIMATIC STEP 7 V17 (All versions < V17 Update 7), SIMATIC STEP 7 V18 (All versions < V18 Update 2), SIMATIC WinCC Unified V16 (All versions < V16 Update 7), SIMATIC WinCC Unified V17 (All versions < V17 Update 7), SIMATIC WinCC Unified V18 (All versions < V18 Update 2), SIMATIC WinCC V16 (All versions < V16.7), SIMATIC WinCC V17 (All versions < V17.7), SIMATIC WinCC V18 (All versions < V18 Update 2), SIMOCODE ES V16 (All versions < V16 Update 7), SIMOCODE ES V17 (All versions < V17 Update 7), SIMOCODE ES V18 (All versions < V18 Update 2), SIMOTION SCOUT TIA V5.4 SP1 (All versions), SIMOTION SCOUT TIA V5.4 SP3 (All versions), SIMOTION SCOUT TIA V5.5 SP1 (All versions), SINAMICS Startdrive V16 (All versions), SINAMICS Startdrive V17 (All versions), SINAMICS Startdrive V18 (All versions), SIRIUS Safety ES V17 (All versions < V17 Update 7), SIRIUS Safety ES V18 (All versions < V18 Update 2), SIRIUS Soft Starter ES V17 (All versions < V17 Update 7), SIRIUS Soft Starter ES V18 (All versions < V18 Update 2), Soft Starter ES V16 (All versions < V16 Update 7), TIA Portal Cloud V3.0 (All versions < V18 Update 2). Affected applications do not properly restrict the .NET BinaryFormatter when deserializing hardware configuration profiles. This could allow an attacker to cause a type confusion and execute arbitrary code within the affected application. This is the same issue that exists for .NET BinaryFormatter https://docs.microsoft.com/en-us/visualstudio/code-quality/ca2300.

VendorProductVersions

Siemens

SIMATIC STEP 7 Safety V16

affected
0 - < V16 Update 7

Siemens

SIMATIC STEP 7 Safety V17

affected
0 - < V17 Update 7

Siemens

SIMATIC STEP 7 Safety V18

affected
0 - < V18 Update 2

Siemens

SIMATIC STEP 7 V16

affected
0 - < V16 Update 7

Siemens

SIMATIC STEP 7 V17

affected
0 - < V17 Update 7

Siemens

SIMATIC STEP 7 V18

affected
0 - < V18 Update 2

Siemens

SIMATIC WinCC Unified V16

affected
0 - < V16 Update 7

Siemens

SIMATIC WinCC Unified V17

affected
0 - < V17 Update 7

Siemens

SIMATIC WinCC Unified V18

affected
0 - < V18 Update 2

Siemens

SIMATIC WinCC V16

affected
0 - < V16.7

Siemens

SIMATIC WinCC V17

affected
0 - < V17.7

Siemens

SIMATIC WinCC V18

affected
0 - < V18 Update 2

Siemens

SIMOCODE ES V16

affected
0 - < V16 Update 7

Siemens

SIMOCODE ES V17

affected
0 - < V17 Update 7

Siemens

SIMOCODE ES V18

affected
0 - < V18 Update 2

Siemens

SIMOTION SCOUT TIA V5.4 SP1

affected
0 - < *

Siemens

SIMOTION SCOUT TIA V5.4 SP3

affected
0 - < *

Siemens

SIMOTION SCOUT TIA V5.5 SP1

affected
0 - < *

Siemens

SINAMICS Startdrive V16

affected
0 - < *

Siemens

SINAMICS Startdrive V17

affected
0 - < *

Siemens

SINAMICS Startdrive V18

affected
0 - < *

Siemens

SIRIUS Safety ES V17

affected
0 - < V17 Update 7

Siemens

SIRIUS Safety ES V18

affected
0 - < V18 Update 2

Siemens

SIRIUS Soft Starter ES V17

affected
0 - < V17 Update 7

Siemens

SIRIUS Soft Starter ES V18

affected
0 - < V18 Update 2

Siemens

Soft Starter ES V16

affected
0 - < V16 Update 7

Siemens

TIA Portal Cloud V3.0

affected
0 - < V18 Update 2

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C

Attack Vector

Local

Attack Complexity

Low

Privileges Required

High

User Interaction

Required

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now