CVE-2023-29104: Path Traversal
A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2.0 < V2.1). The filename in the upload feature of the web based management of the affected device is susceptible to a path traversal vulnerability. This could allow an authenticated privileged remote attacker to overwrite any file the Linux user ccuser has write access to, or to download any file the Linux user ccuser has read-only access to.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-29104?
CVE-2023-29104 is classified as a medium severity vulnerability due to its path traversal exploitation risk.
How do I fix CVE-2023-29104?
To mitigate CVE-2023-29104, upgrade your Siemens SIMATIC Cloud Connect 7 devices to version 2.1 or higher.
What type of vulnerability is CVE-2023-29104?
CVE-2023-29104 is a path traversal vulnerability affecting the upload feature in the web-based management of specific Siemens devices.
Which versions of SIMATIC Cloud Connect are affected by CVE-2023-29104?
CVE-2023-29104 affects all versions of SIMATIC Cloud Connect 7 CC712 and CC716 from 2.0 to below 2.1.
What are the risks associated with CVE-2023-29104?
Exploitation of CVE-2023-29104 could allow unauthorized access to sensitive files on the affected Siemens devices.