First published: Tue Nov 14 2023(Updated: )
A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). When accessing the Information Server from affected products, the products use an overly permissive CORS policy. This could allow an attacker to trick a legitimate user to trigger unwanted behavior.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Simatic Pcs Neo | <4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-46098 is a vulnerability identified in SIMATIC PCS neo (All versions < V4.1) that allows an attacker to trigger unwanted behavior by exploiting an overly permissive CORS policy.
CVE-2023-46098 has a severity score of 8, which is categorized as high.
CVE-2023-46098 affects all versions of Siemens Simatic Pcs Neo prior to version 4.1.
The CWE-ID for CVE-2023-46098 is 942.
Yes, updating to version 4.1 or above of Siemens Simatic Pcs Neo will fix the vulnerability.