First published: Tue Oct 10 2023(Updated: )
A vulnerability has been identified in SICAM PAS/PQS (All versions >= V8.00 < V8.22). The affected application is installed with specific files and folders with insecure permissions. This could allow an authenticated local attacker to read and modify configuration data in the context of the application process.
Credit: productcert@siemens.com productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Sicam Pas\/pqs | >=8.00<8.22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-38640.
The affected software is Siemens SICAM PAS/PQS with all versions greater than or equal to V8.00 and less than V8.22.
The severity of CVE-2023-38640 is medium with a severity value of 4.4.
An authenticated local attacker can exploit CVE-2023-38640 by reading and modifying configuration data in the context of the application.
Siemens has released a security advisory with mitigations and recommended actions to address the vulnerability. Please refer to the reference link for more information.