CVE-2023-44318: Medium severity Siemens 6gk5205-3bb00-2ab2 Firmware vulnerability
Affected devices use a hardcoded key to obfuscate the configuration backup that an administrator can export from the device. This could allow an authenticated attacker with administrative privileges or an attacker that obtains a configuration backup to extract configuration information from the exported file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-44318?
CVE-2023-44318 is classified as a high severity vulnerability due to its potential for authenticated attacks that can expose critical configuration data.
How do I fix CVE-2023-44318?
To mitigate CVE-2023-44318, ensure the device firmware is updated to a version above 4.5 that resolves this vulnerability.
What devices are affected by CVE-2023-44318?
CVE-2023-44318 affects multiple Siemens devices running specific firmware versions up to 4.5.
Can CVE-2023-44318 be exploited remotely?
CVE-2023-44318 requires authenticated administrative access to exploit, limiting its remote exploitability.
What information can be compromised by CVE-2023-44318?
CVE-2023-44318 allows attackers with the necessary access to extract sensitive configuration information from the affected devices.