CVE-2023-46097: SQL Injection
Published Nov 14, 2023
·Updated
A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). The PUD Manager of affected products does not properly neutralize user provided inputs. This could allow an authenticated adjacent attacker to execute SQL statements in the underlying database.
Affected Software
1 affected component
Siemens Simatic Pcs Neo<4.1
Remediation
Event History
Nov 14, 2023
CVE Published
11:04 AM
Data Sourced
11:04 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2023-46097.
2
What is the affected software version?
The affected software version is SIMATIC PCS neo (All versions < V4.1).
3
What is the severity of CVE-2023-46097?
The severity of CVE-2023-46097 is high.
4
How can an attacker exploit CVE-2023-46097?
An authenticated adjacent attacker can exploit CVE-2023-46097 by executing SQL statements in the underlying database.
5
Is there a fix available for CVE-2023-46097?
Please refer to the reference link provided for information on available fixes for CVE-2023-46097.