CVE-2024-23815: High severity siemens desigo cc vulnerability
A vulnerability has been identified in Desigo CC (All versions if access from Installed Clients to Desigo CC server is allowed from networks outside of a highly protected zone), Desigo CC (All versions if access from Installed Clients to Desigo CC server is only allowed within highly protected zones). The affected server application fails to authenticate specific client requests. Modification of the client binary could allow an unauthenticated remote attacker to execute arbitrary SQL queries on the server database via the event port (default: 4998/tcp)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23815?
CVE-2024-23815 has been classified with a high severity due to potential unauthorized access to sensitive systems.
How do I fix CVE-2024-23815?
To mitigate CVE-2024-23815, ensure that access to the Desigo CC server is restricted to highly protected zones only.
What are the consequences of CVE-2024-23815?
Exploitation of CVE-2024-23815 can lead to unauthorized access and manipulation of critical infrastructure managed by Desigo CC.
Which versions are affected by CVE-2024-23815?
CVE-2024-23815 affects all versions of Siemens Desigo CC when improper access controls are configured.
Is there a patch available for CVE-2024-23815?
Currently, there are no specific patches issued for CVE-2024-23815; mitigation strategies should be employed instead.