Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A vulnerability has been identified in Totally Integrated Automation Portal (TIA Portal) V15 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All versions < V16 Update 7), Totally Integrated Automation Portal (TIA Portal) V17 (All versions < V17 Update 6), Totally Integrated Automation Portal (TIA Portal) V18 (All versions < V18 Update 1). Affected products contain a path traversal vulnerability that could allow the creation or overwrite of arbitrary files in the engineering system. If the user is tricked to open a malicious PC system configuration file, an attacker could exploit this vulnerability to achieve arbitrary code execution.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
Vulnerability Type
输入验证不恰当
Vulnerability Title
Siemens TIA Portal 输入验证错误漏洞
Vulnerability Description
Siemens TIA Portal是德国西门子(Siemens)公司的一个完全集成的自动化门户。TIA Portal 使您可以不受限制地访问从数字规划到集成工程和透明操作的全套数字化自动化服务。 Siemens TIA Portal V15、TIA Portal V16、TIA Portal V17、IA Portal V18 Update 1之前版本存在输入验证错误漏洞。攻击者利用该漏洞在工程系统中创建或覆盖任意文件。
CVSS Information
N/A
Vulnerability Type
N/A