CVE-2023-29103: Medium severity siemens 6gk1411-1ac00 firmware vulnerability
A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC712 (All versions < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions < V2.1). The affected device uses a hard-coded password to protect the diagnostic files. This could allow an authenticated attacker to access protected data.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-29103.
What is the severity of CVE-2023-29103?
The severity of CVE-2023-29103 is medium.
What is affected by CVE-2023-29103?
The affected software is SIMATIC Cloud Connect 7 CC712 and CC716 (All versions < V2.1).
How can I fix CVE-2023-29103?
To fix CVE-2023-29103, apply the latest firmware update for Siemens 6gk1411-1ac00 and Siemens 6gk1411-5ac00.
Where can I find more information about CVE-2023-29103?
You can find more information about CVE-2023-29103 in the Siemens ProductCERT advisory at the following link: [Siemens ProductCERT advisory](https://cert-portal.siemens.com/productcert/pdf/ssa-555292.pdf).