CVE Database
/

CVE-2023-48364

Back to search

CVE-2023-48364

Published: Feb 13, 2024

Modified: Sep 10, 2024

PUBLISHED

CVSS v3.1

6.5

MEDIUM

Description

A vulnerability has been identified in OpenPCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 UC05), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC Route Control V9.1 (All versions < V9.1 SP2 UC05), SIMATIC WinCC Runtime Professional V18 (All versions < V18 Update 4), SIMATIC WinCC Runtime Professional V19 (All versions < V19 Update 2), SIMATIC WinCC V7.4 (All versions), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 15), SIMATIC WinCC V8.0 (All versions < V8.0 Update 4). The implementation of the RPC (Remote Procedure call) communication protocol in the affected products do not properly handle certain malformed RPC messages. An attacker could use this vulnerability to cause a denial of service condition in the RPC server.

VendorProductVersions

Siemens

OpenPCS 7 V9.1

affected
All versions < V9.1 SP2 UC05

Siemens

SIMATIC BATCH V9.1

affected
All versions < V9.1 SP2 UC05

Siemens

SIMATIC PCS 7 V9.1

affected
0 - < V9.1 SP2 UC05

Siemens

SIMATIC Route Control V9.1

affected
All versions < V9.1 SP2 UC05

Siemens

SIMATIC WinCC Runtime Professional V18

affected
0 - < V18 Update 4

Siemens

SIMATIC WinCC Runtime Professional V19

affected
0 - < V19 Update 2

Siemens

SIMATIC WinCC V7.4

affected
0 - < *

Siemens

SIMATIC WinCC V7.5

affected
0 - < V7.5 SP2 Update 15

Siemens

SIMATIC WinCC V8.0

affected
0 - < V8.0 Update 4

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C

Attack Vector

Adjacent

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

None

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now