CVE-2023-50821: Medium severity Siemens SIMATIC PCS 7 vulnerability
A vulnerability has been identified in SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC04), SIMATIC WinCC Runtime Professional V17 (All versions < V17 Update 8), SIMATIC WinCC Runtime Professional V18 (All versions < V18 Update 4), SIMATIC WinCC Runtime Professional V19 (All versions < V19 Update 1), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 16), SIMATIC WinCC V8.0 (All versions < V8.0 Update 5). The affected products do not properly validate the input provided in the login dialog box. An attacker could leverage this vulnerability to cause a persistent denial of service condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50821?
CVE-2023-50821 has been classified with a medium severity level due to its potential impact on industrial control systems.
How do I fix CVE-2023-50821?
To address CVE-2023-50821, upgrade to supported versions of the affected software as specified in the security advisory.
Which versions are affected by CVE-2023-50821?
CVE-2023-50821 affects all versions of SIMATIC PCS 7 prior to V9.1 SP2 UC04 and several versions of SIMATIC WinCC Runtime Professional.
What types of software does CVE-2023-50821 impact?
CVE-2023-50821 impacts Siemens SIMATIC PCS 7 and various versions of SIMATIC WinCC Runtime Professional.
Is there a workaround for CVE-2023-50821?
No specific workaround is recommended for CVE-2023-50821, so it is best to upgrade the software to mitigate the vulnerability.