CVE-2023-38533: Medium severity siemens tia administrator vulnerability
A vulnerability has been identified in TIA Administrator (All versions < V3 SP2). The affected component creates temporary download files in a directory with insecure permissions. This could allow any authenticated attacker on Windows to disrupt the update process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-38533?
CVE-2023-38533 is considered a high-severity vulnerability due to its potential to allow authenticated attackers to disrupt the update process.
How do I fix CVE-2023-38533?
To fix CVE-2023-38533, update TIA Administrator to version V3 SP2 or later to eliminate insecure file permission issues.
Who is affected by CVE-2023-38533?
CVE-2023-38533 affects all versions of TIA Administrator prior to V3 SP2 on Windows systems.
What could an attacker do with CVE-2023-38533?
An authenticated attacker could exploit CVE-2023-38533 to disrupt the update process by manipulating temporary download files.
Is CVE-2023-38533 related to file permissions?
Yes, CVE-2023-38533 is related to insecure permissions for temporary download files in TIA Administrator.