First published: Tue Jun 11 2024(Updated: )
A vulnerability has been identified in TIA Administrator (All versions < V3 SP2). The affected component creates temporary download files in a directory with insecure permissions. This could allow any authenticated attacker on Windows to disrupt the update process.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens TIA Administrator | <V3 SP2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-38533 is considered a high-severity vulnerability due to its potential to allow authenticated attackers to disrupt the update process.
To fix CVE-2023-38533, update TIA Administrator to version V3 SP2 or later to eliminate insecure file permission issues.
CVE-2023-38533 affects all versions of TIA Administrator prior to V3 SP2 on Windows systems.
An authenticated attacker could exploit CVE-2023-38533 to disrupt the update process by manipulating temporary download files.
Yes, CVE-2023-38533 is related to insecure permissions for temporary download files in TIA Administrator.