CVE-2023-29106: Infoleak
A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2.0 < V2.1). The export endpoint is accessible via REST API without authentication. This could allow an unauthenticated remote attacker to download the files available via the endpoint.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-29106?
CVE-2023-29106 is considered a high severity vulnerability due to the potential for unauthenticated remote access to sensitive data.
How do I fix CVE-2023-29106?
To fix CVE-2023-29106, it is recommended to upgrade to versions 2.1 or later of SIMATIC Cloud Connect 7 CC712 and CC716.
What systems are affected by CVE-2023-29106?
CVE-2023-29106 affects all versions of SIMATIC Cloud Connect 7 CC712 and CC716 from version 2.0 up to but not including version 2.1.
What type of attack can exploit CVE-2023-29106?
CVE-2023-29106 can be exploited by an unauthenticated remote attacker to access and download data via the REST API.
Is there a workaround for CVE-2023-29106?
Currently, no specific workaround is provided for CVE-2023-29106 besides upgrading to a fixed version.