CVE-2023-51438: Input Validation
A vulnerability has been identified in SIMATIC IPC1047E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPC647E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPC847E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows). In default installations of maxView Storage Manager where Redfish® server is configured for remote system management, a vulnerability has been identified that can provide unauthorized access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-51438?
CVE-2023-51438 has been classified with a medium severity level due to potential unauthorized access risks.
How do I fix CVE-2023-51438?
To fix CVE-2023-51438, update the MaxView Storage Manager to version 4.14.00.26068 or above.
Which products are affected by CVE-2023-51438?
CVE-2023-51438 affects Siemens SIMATIC IPC1047E, IPC647E, and IPC847E models with MaxView Storage Manager versions lower than 4.14.00.26068.
Is there a workaround for CVE-2023-51438?
Currently, there are no documented workarounds for CVE-2023-51438; updating software is the advised course of action.
What impact does CVE-2023-51438 have on my system?
The impact of CVE-2023-51438 may lead to unauthorized access, compromising the integrity and confidentiality of data on affected systems.