PT-2023-6557 · Siemens · Tia Portal

Michael Heinzl

·

Published

2023-04-11

·

Updated

2024-08-13

·

CVE-2023-26293

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Totally Integrated Automation Portal (TIA Portal) versions V15 through V18 Update 1, with the following specifics: TIA Portal versions V15 TIA Portal versions V16 through V16 Update 7 TIA Portal versions V17 through V17 Update 6 TIA Portal versions V18 through V18 Update 1
Description A path traversal vulnerability has been identified in the Totally Integrated Automation Portal (TIA Portal) that could allow the creation or overwrite of arbitrary files in the engineering system. If a user is tricked into opening a malicious PC system configuration file, an attacker could exploit this vulnerability to achieve arbitrary code execution.
Recommendations For TIA Portal version V15, update to a version later than V15. For TIA Portal versions V16 through V16 Update 7, update to V16 Update 7 or later. For TIA Portal versions V17 through V17 Update 6, update to V17 Update 6 or later. For TIA Portal versions V18 through V18 Update 1, update to V18 Update 1 or later.

Fix

RCE

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2023-07319
CVE-2023-26293

Affected Products

Tia Portal