PT-2023-6557 · Siemens · Tia Portal
Michael Heinzl
·
Published
2023-04-11
·
Updated
2024-08-13
·
CVE-2023-26293
CVSS v3.1
7.3
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Totally Integrated Automation Portal (TIA Portal) versions V15 through V18 Update 1, with the following specifics:
TIA Portal versions V15
TIA Portal versions V16 through V16 Update 7
TIA Portal versions V17 through V17 Update 6
TIA Portal versions V18 through V18 Update 1
Description
A path traversal vulnerability has been identified in the Totally Integrated Automation Portal (TIA Portal) that could allow the creation or overwrite of arbitrary files in the engineering system. If a user is tricked into opening a malicious PC system configuration file, an attacker could exploit this vulnerability to achieve arbitrary code execution.
Recommendations
For TIA Portal version V15, update to a version later than V15.
For TIA Portal versions V16 through V16 Update 7, update to V16 Update 7 or later.
For TIA Portal versions V17 through V17 Update 6, update to V17 Update 6 or later.
For TIA Portal versions V18 through V18 Update 1, update to V18 Update 1 or later.
Fix
RCE
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tia Portal