CVE-2023-46096: Medium severity siemens simatic pcs neo firmware vulnerability
Published Nov 14, 2023
·Updated
A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). The PUD Manager of affected products does not properly authenticate users in the PUD Manager web service. This could allow an unauthenticated adjacent attacker to generate a privileged token and upload additional documents.
Affected Software
1 affected component
Siemens Simatic Pcs Neo<4.1
Remediation
Event History
Nov 14, 2023
CVE Published
11:04 AM
Data Sourced
11:04 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-46096.
2
What is the affected software?
The affected software is Siemens Simatic PCS neo versions up to exclusive 4.1.
3
What is the severity of CVE-2023-46096?
The severity of CVE-2023-46096 is medium with a CVSS score of 6.5.
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-306.
5
How can I fix this vulnerability?
To fix this vulnerability, it is recommended to upgrade Siemens Simatic PCS neo to version 4.1 or higher.