CVE Database
/

CVE-2023-50821

Back to search

CVE-2023-50821

Published: Apr 9, 2024

Modified: Feb 26, 2025

PUBLISHED

CVSS v3.1

6.2

MEDIUM

Description

A vulnerability has been identified in SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC04), SIMATIC WinCC Runtime Professional V17 (All versions < V17 Update 8), SIMATIC WinCC Runtime Professional V18 (All versions < V18 Update 4), SIMATIC WinCC Runtime Professional V19 (All versions < V19 Update 1), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 16), SIMATIC WinCC V8.0 (All versions < V8.0 Update 5). The affected products do not properly validate the input provided in the login dialog box. An attacker could leverage this vulnerability to cause a persistent denial of service condition.

VendorProductVersions

Siemens

SIMATIC PCS 7 V9.1

affected
0 - < V9.1 SP2 UC04

Siemens

SIMATIC WinCC Runtime Professional V17

affected
0 - < V17 Update 8

Siemens

SIMATIC WinCC Runtime Professional V18

affected
0 - < V18 Update 4

Siemens

SIMATIC WinCC Runtime Professional V19

affected
0 - < V19 Update 1

Siemens

SIMATIC WinCC V7.5

affected
0 - < V7.5 SP2 Update 16

Siemens

SIMATIC WinCC V8.0

affected
0 - < V8.0 Update 5

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C

Attack Vector

Local

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

None

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now