CVE-2023-30897: High severity siemens wincc vulnerability
A vulnerability has been identified in SIMATIC WinCC (All versions < V7.5.2.13). Affected applications fail to set proper access rights for their installation folder if a non-default installation path was chosen during installation. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-30897?
CVE-2023-30897 has been assigned a high severity rating due to the potential for authenticated local attackers to exploit access rights issues.
How do I fix CVE-2023-30897?
To fix CVE-2023-30897, ensure that the assembly folder permissions are properly configured following the latest installation guidelines.
What versions of SIMATIC WinCC are affected by CVE-2023-30897?
CVE-2023-30897 affects all versions of SIMATIC WinCC prior to version 7.5.2.13.
Can CVE-2023-30897 be exploited remotely?
No, CVE-2023-30897 requires local access, meaning it cannot be exploited remotely by an attacker.
Who can exploit CVE-2023-30897?
CVE-2023-30897 can be exploited by authenticated local users with sufficient privileges to access the installation folder.