Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2023-46280

Quick assessment

Affected
Siemens Security Configuration Tool (SCT)
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Siemens SIMATIC PCS是德国西门子(Siemens)公司的一套过程控制系统。 Siemens 多款产品存在缓冲区错误漏洞,该漏洞源于受影响的应用程序包含越界读取漏洞。以下产品及版本受到影响:S7-PCT,SIMATIC BATCH V9.1,SIMATIC PCS 7 V9.1,SIMATIC Route Control V9.1,SIMATIC WinCC OA V3.17,SIMATIC WinCC OA V3.19,SIMATIC WinCC Runtime Advanced,SIM

CVSS 6.5 · Medium EPSS 0.26% · P16

Affected Version Matrix 34

VendorProduct Version RangeStatus
Siemens Security Configuration Tool (SCT) < * affected
Siemens SIMATIC Automation Tool < V5.0 SP2 affected
Siemens SIMATIC BATCH V9.1 < V9.1 SP2 Upd5 affected
Siemens SIMATIC NET PC Software V16 < V16 Update 8 affected
Siemens SIMATIC NET PC Software V17 < * affected
Siemens SIMATIC NET PC Software V18 < V18 SP1 affected
Siemens SIMATIC NET PC Software V19 < V19 Update 2 affected
Siemens SIMATIC PCS 7 V9.1 < V9.1 SP2 UC05 affected
Siemens SIMATIC PDM V9.2 < V9.2 SP2 Upd3 affected
Siemens SIMATIC Route Control V9.1 < V9.1 SP2 Upd3 affected
Siemens SIMATIC S7-PCT < V3.5 SP3 Update 6 affected
Siemens SIMATIC STEP 7 V5 < V5.7 SP3 affected
Siemens SIMATIC WinCC OA V3.17 < * affected
Siemens SIMATIC WinCC OA V3.18 < V3.18 P025 affected
Siemens SIMATIC WinCC OA V3.19 < V3.19 P010 affected
Siemens SIMATIC WinCC Runtime Advanced < V17 Update 8 affected
Siemens SIMATIC WinCC Runtime Professional V16 < V16 Update 6 affected
Siemens SIMATIC WinCC Runtime Professional V17 < V17 Update 8 affected
Siemens SIMATIC WinCC Runtime Professional V18 < V18 Update 4 affected
Siemens SIMATIC WinCC Runtime Professional V19 < V19 Update 2 affected
Siemens SIMATIC WinCC V7.4 < * affected
Siemens SIMATIC WinCC V7.5 < V7.5 SP2 Update 17 affected
Siemens SIMATIC WinCC V8.0 < V8.0 Update 5 affected
Siemens SINAMICS Startdrive < V19 SP1 affected
Siemens SINEC NMS < V3.0 affected
< V3.0 SP1 affected
Siemens SINUMERIK ONE virtual < V6.23 affected
Siemens SINUMERIK PLC Programming Tool < V3.3.12 affected
Siemens TIA Portal Cloud Connector < V2.0 affected
Siemens Totally Integrated Automation Portal (TIA Portal) V15.1 < * affected
Siemens Totally Integrated Automation Portal (TIA Portal) V16 < * affected
Siemens Totally Integrated Automation Portal (TIA Portal) V17 < V17 Update 8 affected
Siemens Totally Integrated Automation Portal (TIA Portal) V18 < V18 Update 4 affected
Siemens Totally Integrated Automation Portal (TIA Portal) V19 < V19 Update 2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2023-46280

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability has been identified in Security Configuration Tool (SCT) (All versions), SIMATIC Automation Tool (All versions < V5.0 SP2), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 Upd5), SIMATIC NET PC Software V16 (All versions < V16 Update 8), SIMATIC NET PC Software V17 (All versions), SIMATIC NET PC Software V18 (All versions < V18 SP1), SIMATIC NET PC Software V19 (All versions < V19 Update 2), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC PDM V9.2 (All versions < V9.2 SP2 Upd3), SIMATIC Route Control V9.1 (All versions < V9.1 SP2 Upd3), SIMATIC S7-PCT (All versions < V3.5 SP3 Update 6), SIMATIC STEP 7 V5 (All versions < V5.7 SP3), SIMATIC WinCC OA V3.17 (All versions), SIMATIC WinCC OA V3.18 (All versions < V3.18 P025), SIMATIC WinCC OA V3.19 (All versions < V3.19 P010), SIMATIC WinCC Runtime Advanced (All versions < V17 Update 8), SIMATIC WinCC Runtime Professional V16 (All versions < V16 Update 6), SIMATIC WinCC Runtime Professional V17 (All versions < V17 Update 8), SIMATIC WinCC Runtime Professional V18 (All versions < V18 Update 4), SIMATIC WinCC Runtime Professional V19 (All versions < V19 Update 2), SIMATIC WinCC V7.4 (All versions), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 17), SIMATIC WinCC V8.0 (All versions < V8.0 Update 5), SINAMICS Startdrive (All versions < V19 SP1), SINEC NMS (All versions < V3.0), SINUMERIK ONE virtual (All versions < V6.23), SINUMERIK PLC Programming Tool (All versions < V3.3.12), TIA Portal Cloud Connector (All versions < V2.0), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions < V17 Update 8), Totally Integrated Automation Portal (TIA Portal) V18 (All versions < V18 Update 4), Totally Integrated Automation Portal (TIA Portal) V19 (All versions < V19 Update 2), SINEC NMS (All versions < V3.0 SP1). The affected applications contain an out of bounds read vulnerability. This could allow an attacker to cause a Blue Screen of Death (BSOD) crash of the underlying Windows kernel.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存读
Source: CVE Program / CVE List V5
Vulnerability Title
Siemens 多款产品 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Siemens SIMATIC PCS是德国西门子(Siemens)公司的一套过程控制系统。 Siemens 多款产品存在缓冲区错误漏洞,该漏洞源于受影响的应用程序包含越界读取漏洞。以下产品及版本受到影响:S7-PCT,SIMATIC BATCH V9.1,SIMATIC PCS 7 V9.1,SIMATIC Route Control V9.1,SIMATIC WinCC OA V3.17,SIMATIC WinCC OA V3.19,SIMATIC WinCC Runtime Advanced,SIM
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Siemens Security Configuration Tool (SCT) 0 ~ * -
Siemens SIMATIC Automation Tool 0 ~ V5.0 SP2 -
Siemens SIMATIC BATCH V9.1 0 ~ V9.1 SP2 Upd5 -
Siemens SIMATIC NET PC Software V16 0 ~ V16 Update 8 -
Siemens SIMATIC NET PC Software V17 0 ~ * -
Siemens SIMATIC NET PC Software V18 0 ~ V18 SP1 -
Siemens SIMATIC NET PC Software V19 0 ~ V19 Update 2 -
Siemens SIMATIC PCS 7 V9.1 0 ~ V9.1 SP2 UC05 -
Siemens SIMATIC PDM V9.2 0 ~ V9.2 SP2 Upd3 -
Siemens SIMATIC Route Control V9.1 0 ~ V9.1 SP2 Upd3 -
Siemens SIMATIC S7-PCT 0 ~ V3.5 SP3 Update 6 -
Siemens SIMATIC STEP 7 V5 0 ~ V5.7 SP3 -
Siemens SIMATIC WinCC OA V3.17 0 ~ * -
Siemens SIMATIC WinCC OA V3.18 0 ~ V3.18 P025 -
Siemens SIMATIC WinCC OA V3.19 0 ~ V3.19 P010 -
Siemens SIMATIC WinCC Runtime Advanced 0 ~ V17 Update 8 -
Siemens SIMATIC WinCC Runtime Professional V16 0 ~ V16 Update 6 -
Siemens SIMATIC WinCC Runtime Professional V17 0 ~ V17 Update 8 -
Siemens SIMATIC WinCC Runtime Professional V18 0 ~ V18 Update 4 -
Siemens SIMATIC WinCC Runtime Professional V19 0 ~ V19 Update 2 -
Siemens SIMATIC WinCC V7.4 0 ~ * -
Siemens SIMATIC WinCC V7.5 0 ~ V7.5 SP2 Update 17 -
Siemens SIMATIC WinCC V8.0 0 ~ V8.0 Update 5 -
Siemens SINAMICS Startdrive 0 ~ V19 SP1 -
Siemens SINEC NMS 0 ~ V3.0 -
Siemens SINUMERIK ONE virtual 0 ~ V6.23 -
Siemens SINUMERIK PLC Programming Tool 0 ~ V3.3.12 -
Siemens TIA Portal Cloud Connector 0 ~ V2.0 -
Siemens Totally Integrated Automation Portal (TIA Portal) V15.1 0 ~ * -
Siemens Totally Integrated Automation Portal (TIA Portal) V16 0 ~ * -

II. Public POCs for CVE-2023-46280

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-46280

请登录查看更多情报信息。

Vendor Advisories for CVE-2023-46280 (3)

Same Patch Batch · Siemens · 2024-05-14 · 55 CVEs total

CVE-2024-32741 10.0 CRITICAL Siemens SIMATIC CN 4100 安全漏洞
CVE-2024-30207 10.0 CRITICAL Siemens 多款产品 安全漏洞
CVE-2024-32740 9.8 CRITICAL Siemens SIMATIC CN 4100 信任管理问题漏洞
CVE-2024-27939 9.8 CRITICAL Siemens RUGGEDCOM CROSSBOW 安全漏洞
CVE-2024-30209 9.6 CRITICAL Siemens 多款产品 安全漏洞
CVE-2024-33499 9.1 CRITICAL Siemens 多款产品 安全漏洞
CVE-2024-30206 8.8 HIGH Siemens 多款产品 安全漏洞
CVE-2024-27940 8.8 HIGH Siemens RUGGEDCOM CROSSBOW SQL注入漏洞
CVE-2024-27941 8.8 HIGH Siemens RUGGEDCOM CROSSBOW SQL注入漏洞
CVE-2024-34772 7.8 HIGH Siemens Solid Edge 缓冲区错误漏洞
CVE-2024-34771 7.8 HIGH Siemens Solid Edge 安全漏洞
CVE-2024-34086 7.8 HIGH Siemens 多款产品 缓冲区错误漏洞
CVE-2024-33489 7.8 HIGH Siemens Solid Edge 安全漏洞
CVE-2024-34773 7.8 HIGH Siemens Solid Edge 安全漏洞
CVE-2024-32639 7.8 HIGH Siemens Tecnomatix Plant Simulation 缓冲区错误漏洞
CVE-2024-32636 7.8 HIGH Siemens 多款产品 缓冲区错误漏洞
CVE-2024-32635 7.8 HIGH Siemens 多款产品 缓冲区错误漏洞
CVE-2024-32066 7.8 HIGH Siemens Parasolid 缓冲区错误漏洞
CVE-2024-32065 7.8 HIGH Siemens Parasolid 缓冲区错误漏洞
CVE-2024-33490 7.8 HIGH Siemens Solid Edge 缓冲区错误漏洞

Showing top 20 of 55 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2023-46280

No comments yet


Leave a comment