PT-2023-3371 · Siemens · Simatic S7-Pm+2

Thomas Riedmaier

·

Publicado

2023-06-13

·

Atualizado

2024-05-14

·

CVE-2023-25910

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SIMATIC PCS 7 versions prior to V9.1 SP2 UC04 SIMATIC S7-PM versions prior to V5.7 SP1 HF1 SIMATIC S7-PM versions prior to V5.7 SP2 HF1 SIMATIC STEP 7 V5 versions prior to V5.7
Description A vulnerability has been identified in the affected products, which contain a database management system that could allow remote users with low privileges to use embedded functions of the database, potentially impacting the server. An attacker with network access to the server network could leverage these embedded functions to run code with elevated privileges in the database management system's server. The issue is related to incorrect code generation management.
Recommendations For SIMATIC PCS 7 versions prior to V9.1 SP2 UC04, update to V9.1 SP2 UC04 or later. For SIMATIC S7-PM versions prior to V5.7 SP1 HF1, update to V5.7 SP1 HF1 or later. For SIMATIC S7-PM versions prior to V5.7 SP2 HF1, update to V5.7 SP2 HF1 or later. For SIMATIC STEP 7 V5 versions prior to V5.7, update to V5.7 or later.

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-03527
CVE-2023-25910

Produtos afetados

Simatic Pcs 7
Simatic S7-Pm
Simatic Step 7 V5