CVE-2023-46098: High severity siemens simatic pcs neo firmware vulnerability
Published Nov 14, 2023
·Updated
A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). When accessing the Information Server from affected products, the products use an overly permissive CORS policy. This could allow an attacker to trick a legitimate user to trigger unwanted behavior.
Affected Software
1 affected component
Siemens Simatic Pcs Neo<4.1
Remediation
Event History
Nov 14, 2023
CVE Published
11:04 AM
Data Sourced
11:04 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-46098?
CVE-2023-46098 is a vulnerability identified in SIMATIC PCS neo (All versions < V4.1) that allows an attacker to trigger unwanted behavior by exploiting an overly permissive CORS policy.
2
How severe is CVE-2023-46098?
CVE-2023-46098 has a severity score of 8, which is categorized as high.
3
How does CVE-2023-46098 affect Siemens Simatic Pcs Neo?
CVE-2023-46098 affects all versions of Siemens Simatic Pcs Neo prior to version 4.1.
4
What is the CWE-ID for CVE-2023-46098?
The CWE-ID for CVE-2023-46098 is 942.
5
Is there a solution available for CVE-2023-46098?
Yes, updating to version 4.1 or above of Siemens Simatic Pcs Neo will fix the vulnerability.