PT-2023-3371 · Siemens · Simatic S7-Pm+2
Thomas Riedmaier
·
Published
2023-06-13
·
Updated
2024-05-14
·
CVE-2023-25910
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SIMATIC PCS 7 versions prior to V9.1 SP2 UC04
SIMATIC S7-PM versions prior to V5.7 SP1 HF1
SIMATIC S7-PM versions prior to V5.7 SP2 HF1
SIMATIC STEP 7 V5 versions prior to V5.7
Description
A vulnerability has been identified in the affected products, which contain a database management system that could allow remote users with low privileges to use embedded functions of the database, potentially impacting the server. An attacker with network access to the server network could leverage these embedded functions to run code with elevated privileges in the database management system's server. The issue is related to incorrect code generation management.
Recommendations
For SIMATIC PCS 7 versions prior to V9.1 SP2 UC04, update to V9.1 SP2 UC04 or later.
For SIMATIC S7-PM versions prior to V5.7 SP1 HF1, update to V5.7 SP1 HF1 or later.
For SIMATIC S7-PM versions prior to V5.7 SP2 HF1, update to V5.7 SP2 HF1 or later.
For SIMATIC STEP 7 V5 versions prior to V5.7, update to V5.7 or later.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simatic Pcs 7
Simatic S7-Pm
Simatic Step 7 V5