PT-2023-22155 · Siemens · Simatic Cloud Connect 7 Cc716+1
CVE-2023-29107
·
Publicado
2023-05-09
·
Atualizado
2023-05-15
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SIMATIC Cloud Connect 7 CC712 versions 2.0 through 2.1
SIMATIC Cloud Connect 7 CC716 versions 2.0 through 2.1
Description
A vulnerability has been identified that could allow an unauthenticated remote attacker to gain access to additional information resources. The export endpoint discloses some undocumented files.
Recommendations
For SIMATIC Cloud Connect 7 CC712 versions 2.0 through 2.1, consider restricting access to the export endpoint until a fix is available.
For SIMATIC Cloud Connect 7 CC716 versions 2.0 through 2.1, consider restricting access to the export endpoint until a fix is available.
Correção
Files Accessible to External Parties
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Simatic Cloud Connect 7 Cc712
Simatic Cloud Connect 7 Cc716