First published: Thu Sep 14 2023(Updated: )
A vulnerability has been identified in SIMATIC PCS neo (Administration Console) V4.0 (All versions), SIMATIC PCS neo (Administration Console) V4.0 Update 1 (All versions). The affected application leaks Windows admin credentials. An attacker with local access to the Administration Console could get the credentials, and impersonate the admin user, thereby gaining admin access to other Windows systems.
Credit: productcert@siemens.com productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Simatic Pcs Neo | =4.0 | |
Siemens Simatic Pcs Neo | =4.0-update_1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-38558.
The title of this vulnerability is 'A vulnerability has been identified in SIMATIC PCS neo (Administration Console) V4.0 (All versions)'.
The severity of CVE-2023-38558 is medium, with a severity value of 5.5.
SIMATIC PCS neo (Administration Console) V4.0 and SIMATIC PCS neo (Administration Console) V4.0 Update 1 are affected by CVE-2023-38558.
The vulnerability in SIMATIC PCS neo (Administration Console) V4.0 leaks Windows admin credentials, allowing an attacker with local access to the Administration Console to obtain them.
To fix CVE-2023-38558, it is recommended to apply the necessary patches and updates provided by Siemens.