CVE-2023-51438
Published: Jan 9, 2024
Modified: May 22, 2025
CVSS v3.1
10.0
Description
A vulnerability has been identified in SIMATIC IPC1047E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPC647E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPC847E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows). In default installations of maxView Storage Manager where Redfish® server is configured for remote system management, a vulnerability has been identified that can provide unauthorized access.
| Vendor | Product | Versions |
|---|---|---|
Siemens | SIMATIC IPC1047E | affected All versions with maxView Storage Manager < V4.14.00.26068 on Windows |
Siemens | SIMATIC IPC647E | affected All versions with maxView Storage Manager < V4.14.00.26068 on Windows |
Siemens | SIMATIC IPC847E | affected All versions with maxView Storage Manager < V4.14.00.26068 on Windows |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now