Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-44373

CVSS 9.1 · Critical EPSS 0.53% · P68
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-44373

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject code or spawn a system root shell. Follow-up of CVE-2022-36323.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
输出中的特殊元素转义处理不恰当(注入)
Source: NVD (National Vulnerability Database)
Vulnerability Title
Siemens 多款产品 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Siemens SCALANCE是德国西门子(Siemens)公司的一系列以太网交换机。可连接到工业控制系统 (ICS) 设备,包括可编程逻辑控制器 (PLC) 和人机界面 (HMI) 系统。 Siemens 多款产品存在安全漏洞,该漏洞源于受影响的设备无法正确清理输入字段。以下产品及版本受到影响:SCALANCE XB205-3 (SC, PN), SCALANCE XB205-3 (ST, E/IP), SCALANCE XB205-3 (ST, E/IP), SCALANCE XB205-3 (ST
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
SiemensRUGGEDCOM RM1224 LTE(4G) EU 0 ~ V8.0 -
SiemensRUGGEDCOM RM1224 LTE(4G) NAM 0 ~ V8.0 -
SiemensSCALANCE M804PB 0 ~ V8.0 -
SiemensSCALANCE M812-1 ADSL-Router 0 ~ V8.0 -
SiemensSCALANCE M812-1 ADSL-Router 0 ~ V8.0 -
SiemensSCALANCE M816-1 ADSL-Router 0 ~ V8.0 -
SiemensSCALANCE M816-1 ADSL-Router 0 ~ V8.0 -
SiemensSCALANCE M826-2 SHDSL-Router 0 ~ V8.0 -
SiemensSCALANCE M874-2 0 ~ V8.0 -
SiemensSCALANCE M874-3 0 ~ V8.0 -
SiemensSCALANCE M876-3 0 ~ V8.0 -
SiemensSCALANCE M876-3 (ROK) 0 ~ V8.0 -
SiemensSCALANCE M876-4 0 ~ V8.0 -
SiemensSCALANCE M876-4 (EU) 0 ~ V8.0 -
SiemensSCALANCE M876-4 (NAM) 0 ~ V8.0 -
SiemensSCALANCE MUM853-1 (EU) 0 ~ V8.0 -
SiemensSCALANCE MUM856-1 (EU) 0 ~ V8.0 -
SiemensSCALANCE MUM856-1 (RoW) 0 ~ V8.0 -
SiemensSCALANCE S615 EEC LAN-Router 0 ~ V8.0 -
SiemensSCALANCE S615 LAN-Router 0 ~ V8.0 -
SiemensSCALANCE W721-1 RJ45 0 ~ V6.6.0 -
SiemensSCALANCE W721-1 RJ45 0 ~ V6.6.0 -
SiemensSCALANCE W722-1 RJ45 0 ~ V6.6.0 -
SiemensSCALANCE W722-1 RJ45 0 ~ V6.6.0 -
SiemensSCALANCE W722-1 RJ45 0 ~ V6.6.0 -
SiemensSCALANCE W734-1 RJ45 0 ~ V6.6.0 -
SiemensSCALANCE W734-1 RJ45 0 ~ V6.6.0 -
SiemensSCALANCE W734-1 RJ45 0 ~ V6.6.0 -
SiemensSCALANCE W734-1 RJ45 (USA) 0 ~ V6.6.0 -
SiemensSCALANCE W738-1 M12 0 ~ V6.6.0 -
SiemensSCALANCE W738-1 M12 0 ~ V6.6.0 -
SiemensSCALANCE W748-1 M12 0 ~ V6.6.0 -
SiemensSCALANCE W748-1 M12 0 ~ V6.6.0 -
SiemensSCALANCE W748-1 RJ45 0 ~ V6.6.0 -
SiemensSCALANCE W748-1 RJ45 0 ~ V6.6.0 -
SiemensSCALANCE W761-1 RJ45 0 ~ V6.6.0 -
SiemensSCALANCE W761-1 RJ45 0 ~ V6.6.0 -
SiemensSCALANCE W774-1 M12 EEC 0 ~ V6.6.0 -
SiemensSCALANCE W774-1 M12 EEC 0 ~ V6.6.0 -
SiemensSCALANCE W774-1 RJ45 0 ~ V6.6.0 -
SiemensSCALANCE W774-1 RJ45 0 ~ V6.6.0 -
SiemensSCALANCE W774-1 RJ45 0 ~ V6.6.0 -
SiemensSCALANCE W774-1 RJ45 0 ~ V6.6.0 -
SiemensSCALANCE W774-1 RJ45 (USA) 0 ~ V6.6.0 -
SiemensSCALANCE W778-1 M12 0 ~ V6.6.0 -
SiemensSCALANCE W778-1 M12 0 ~ V6.6.0 -
SiemensSCALANCE W778-1 M12 EEC 0 ~ V6.6.0 -
SiemensSCALANCE W778-1 M12 EEC (USA) 0 ~ V6.6.0 -
SiemensSCALANCE W786-1 RJ45 0 ~ V6.6.0 -
SiemensSCALANCE W786-1 RJ45 0 ~ V6.6.0 -
SiemensSCALANCE W786-2 RJ45 0 ~ V6.6.0 -
SiemensSCALANCE W786-2 RJ45 0 ~ V6.6.0 -
SiemensSCALANCE W786-2 RJ45 0 ~ V6.6.0 -
SiemensSCALANCE W786-2 SFP 0 ~ V6.6.0 -
SiemensSCALANCE W786-2 SFP 0 ~ V6.6.0 -
SiemensSCALANCE W786-2IA RJ45 0 ~ V6.6.0 -
SiemensSCALANCE W786-2IA RJ45 0 ~ V6.6.0 -
SiemensSCALANCE W788-1 M12 0 ~ V6.6.0 -
SiemensSCALANCE W788-1 M12 0 ~ V6.6.0 -
SiemensSCALANCE W788-1 RJ45 0 ~ V6.6.0 -
SiemensSCALANCE W788-1 RJ45 0 ~ V6.6.0 -
SiemensSCALANCE W788-2 M12 0 ~ V6.6.0 -
SiemensSCALANCE W788-2 M12 0 ~ V6.6.0 -
SiemensSCALANCE W788-2 M12 EEC 0 ~ V6.6.0 -
SiemensSCALANCE W788-2 M12 EEC 0 ~ V6.6.0 -
SiemensSCALANCE W788-2 M12 EEC 0 ~ V6.6.0 -
SiemensSCALANCE W788-2 RJ45 0 ~ V6.6.0 -
SiemensSCALANCE W788-2 RJ45 0 ~ V6.6.0 -
SiemensSCALANCE W788-2 RJ45 0 ~ V6.6.0 -
SiemensSCALANCE WAB762-1 0 ~ V2.4.0 -
SiemensSCALANCE WAM763-1 0 ~ V2.4.0 -
SiemensSCALANCE WAM763-1 (ME) 0 ~ V2.4.0 -
SiemensSCALANCE WAM763-1 (US) 0 ~ V2.4.0 -
SiemensSCALANCE WAM766-1 0 ~ V2.4.0 -
SiemensSCALANCE WAM766-1 (ME) 0 ~ V2.4.0 -
SiemensSCALANCE WAM766-1 (US) 0 ~ V2.4.0 -
SiemensSCALANCE WAM766-1 EEC 0 ~ V2.4.0 -
SiemensSCALANCE WAM766-1 EEC (ME) 0 ~ V2.4.0 -
SiemensSCALANCE WAM766-1 EEC (US) 0 ~ V2.4.0 -
SiemensSCALANCE WUB762-1 0 ~ V2.4.0 -
SiemensSCALANCE WUB762-1 iFeatures 0 ~ V2.4.0 -
SiemensSCALANCE WUM763-1 0 ~ V2.4.0 -
SiemensSCALANCE WUM763-1 0 ~ V2.4.0 -
SiemensSCALANCE WUM763-1 (US) 0 ~ V2.4.0 -
SiemensSCALANCE WUM763-1 (US) 0 ~ V2.4.0 -
SiemensSCALANCE WUM766-1 0 ~ V2.4.0 -
SiemensSCALANCE WUM766-1 (ME) 0 ~ V2.4.0 -
SiemensSCALANCE WUM766-1 (USA) 0 ~ V2.4.0 -

II. Public POCs for CVE-2023-44373

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-44373

登录查看更多情报信息。
Advisory · 5

Same Patch Batch · Siemens · 2023-11-14 · 18 CVEs total

CVE-2023-466019.6 CRITICALSiemens Comos 安全漏洞
CVE-2023-435049.6 CRITICALSiemens Comos 安全漏洞
CVE-2023-435059.6 CRITICALSiemens Comos 安全漏洞
CVE-2023-460988.0 HIGHSiemens SIMATIC PCS 安全漏洞
CVE-2023-465907.5 HIGHSiemens OPC UA Modelling Editor 安全漏洞
CVE-2023-443177.2 HIGHSiemens SCALANCE 多款产品安全漏洞
CVE-2023-457946.8 MEDIUMSiemens Mendix Applications 安全漏洞
CVE-2023-460966.5 MEDIUMSiemens SIMATIC PCS 安全漏洞
CVE-2023-443746.5 MEDIUMSiemens 多款产品 安全漏洞
CVE-2023-460976.3 MEDIUMSiemens SIMATIC PCS 安全漏洞
CVE-2023-460995.4 MEDIUMSiemens SIMATIC PCS 安全漏洞
CVE-2023-443194.9 MEDIUMSiemens 多款产品 安全漏洞
CVE-2023-443184.9 MEDIUMSiemens 多款产品 安全漏洞
CVE-2023-443204.3 MEDIUMSiemens SCALANCE 多款产品安全漏洞
CVE-2023-443223.7 LOWSiemens 多款产品 安全漏洞
CVE-2023-435033.5 LOWSiemens Comos 安全漏洞
CVE-2023-443212.7 LOWSiemens SCALANCE 多款产品安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2023-44373

No comments yet


Leave a comment