CVE-2023-29128: Path Traversal
A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2.0 < V2.1). The filename in the upload feature of the web based management of the affected device is susceptible to a path traversal vulnerability. This could allow an authenticated privileged remote attacker to write any file with the extension .db.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-29128?
CVE-2023-29128 is classified as a medium severity vulnerability due to the potential for unauthorized file access.
How do I fix CVE-2023-29128?
To remediate CVE-2023-29128, upgrade to a version of SIMATIC Cloud Connect 7 CC712 or CC716 that is 2.1 or higher.
What types of devices are affected by CVE-2023-29128?
CVE-2023-29128 affects SIMATIC Cloud Connect 7 CC712 and CC716 devices running versions 2.0 up to but not including 2.1.
What is the nature of the vulnerability in CVE-2023-29128?
CVE-2023-29128 involves a path traversal vulnerability in the filename upload feature of the web-based management interface.
Is there a workaround available for CVE-2023-29128?
There is no specific workaround for CVE-2023-29128, but immediate upgrading of affected devices is the recommended action.