CVE-2023-52891: Medium severity siemens simatic energy manager basic vulnerability
A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.5), SIMATIC Energy Manager PRO (All versions < V7.5), SIMATIC IPC DiagBase (All versions), SIMATIC IPC DiagMonitor (All versions), SIMIT V10 (All versions), SIMIT V11 (All versions < V11.1). Unified Automation .NET based OPC UA Server SDK before 3.2.2 used in Siemens products are affected by a similar vulnerability as documented in CVE-2023-27321 for the OPC Foundation UA .NET Standard implementation. A successful attack may lead to high load situation and memory exhaustion, and may block the server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-52891?
CVE-2023-52891 is classified as a high-severity vulnerability.
How do I fix CVE-2023-52891?
To remediate CVE-2023-52891, upgrade the affected software to version 7.5 or later for SIMATIC Energy Manager Basic and PRO, and to version 11.1 for SIMIT V11.
Which products are affected by CVE-2023-52891?
CVE-2023-52891 affects Siemens SIMATIC Energy Manager Basic, SIMATIC Energy Manager PRO, SIMATIC IPC DiagBase, SIMATIC IPC DiagMonitor, and SIMIT versions older than specified.
Is CVE-2023-52891 a remote vulnerability?
Yes, CVE-2023-52891 can potentially be exploited remotely.
What could happen if I do not address CVE-2023-52891?
If CVE-2023-52891 is not addressed, it could lead to unauthorized access and impact the integrity and availability of the affected systems.