Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-46280

CVSS 6.5 · Medium EPSS 0.05% · P15
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-46280

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
A vulnerability has been identified in Security Configuration Tool (SCT) (All versions), SIMATIC Automation Tool (All versions < V5.0 SP2), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 Upd5), SIMATIC NET PC Software V16 (All versions < V16 Update 8), SIMATIC NET PC Software V17 (All versions), SIMATIC NET PC Software V18 (All versions < V18 SP1), SIMATIC NET PC Software V19 (All versions < V19 Update 2), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC PDM V9.2 (All versions < V9.2 SP2 Upd3), SIMATIC Route Control V9.1 (All versions < V9.1 SP2 Upd3), SIMATIC S7-PCT (All versions < V3.5 SP3 Update 6), SIMATIC STEP 7 V5 (All versions < V5.7 SP3), SIMATIC WinCC OA V3.17 (All versions), SIMATIC WinCC OA V3.18 (All versions < V3.18 P025), SIMATIC WinCC OA V3.19 (All versions < V3.19 P010), SIMATIC WinCC Runtime Advanced (All versions < V17 Update 8), SIMATIC WinCC Runtime Professional V16 (All versions < V16 Update 6), SIMATIC WinCC Runtime Professional V17 (All versions < V17 Update 8), SIMATIC WinCC Runtime Professional V18 (All versions < V18 Update 4), SIMATIC WinCC Runtime Professional V19 (All versions < V19 Update 2), SIMATIC WinCC V7.4 (All versions), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 17), SIMATIC WinCC V8.0 (All versions < V8.0 Update 5), SINAMICS Startdrive (All versions < V19 SP1), SINEC NMS (All versions < V3.0), SINEC NMS (All versions < V3.0 SP1), SINUMERIK ONE virtual (All versions < V6.23), SINUMERIK PLC Programming Tool (All versions < V3.3.12), TIA Portal Cloud Connector (All versions < V2.0), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions < V17 Update 8), Totally Integrated Automation Portal (TIA Portal) V18 (All versions < V18 Update 4), Totally Integrated Automation Portal (TIA Portal) V19 (All versions < V19 Update 2). The affected applications contain an out of bounds read vulnerability. This could allow an attacker to cause a Blue Screen of Death (BSOD) crash of the underlying Windows kernel.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
跨界内存读
Source: NVD (National Vulnerability Database)
Vulnerability Title
Siemens 多款产品 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Siemens SIMATIC PCS是德国西门子(Siemens)公司的一套过程控制系统。 Siemens 多款产品存在缓冲区错误漏洞,该漏洞源于受影响的应用程序包含越界读取漏洞。以下产品及版本受到影响:S7-PCT,SIMATIC BATCH V9.1,SIMATIC PCS 7 V9.1,SIMATIC Route Control V9.1,SIMATIC WinCC OA V3.17,SIMATIC WinCC OA V3.19,SIMATIC WinCC Runtime Advanced,SIM
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
SiemensSecurity Configuration Tool (SCT) 0 ~ * -
SiemensSIMATIC Automation Tool 0 ~ V5.0 SP2 -
SiemensSIMATIC BATCH V9.1 0 ~ V9.1 SP2 Upd5 -
SiemensSIMATIC NET PC Software V16 0 ~ V16 Update 8 -
SiemensSIMATIC NET PC Software V17 0 ~ * -
SiemensSIMATIC NET PC Software V18 0 ~ V18 SP1 -
SiemensSIMATIC NET PC Software V19 0 ~ V19 Update 2 -
SiemensSIMATIC PCS 7 V9.1 0 ~ V9.1 SP2 UC05 -
SiemensSIMATIC PDM V9.2 0 ~ V9.2 SP2 Upd3 -
SiemensSIMATIC Route Control V9.1 0 ~ V9.1 SP2 Upd3 -
SiemensSIMATIC S7-PCT 0 ~ V3.5 SP3 Update 6 -
SiemensSIMATIC STEP 7 V5 0 ~ V5.7 SP3 -
SiemensSIMATIC WinCC OA V3.17 0 ~ * -
SiemensSIMATIC WinCC OA V3.18 0 ~ V3.18 P025 -
SiemensSIMATIC WinCC OA V3.19 0 ~ V3.19 P010 -
SiemensSIMATIC WinCC Runtime Advanced 0 ~ V17 Update 8 -
SiemensSIMATIC WinCC Runtime Professional V16 0 ~ V16 Update 6 -
SiemensSIMATIC WinCC Runtime Professional V17 0 ~ V17 Update 8 -
SiemensSIMATIC WinCC Runtime Professional V18 0 ~ V18 Update 4 -
SiemensSIMATIC WinCC Runtime Professional V19 0 ~ V19 Update 2 -
SiemensSIMATIC WinCC V7.4 0 ~ * -
SiemensSIMATIC WinCC V7.5 0 ~ V7.5 SP2 Update 17 -
SiemensSIMATIC WinCC V8.0 0 ~ V8.0 Update 5 -
SiemensSINAMICS Startdrive 0 ~ V19 SP1 -
SiemensSINEC NMS 0 ~ V3.0 -
SiemensSINEC NMS 0 ~ V3.0 SP1 -
SiemensSINUMERIK ONE virtual 0 ~ V6.23 -
SiemensSINUMERIK PLC Programming Tool 0 ~ V3.3.12 -
SiemensTIA Portal Cloud Connector 0 ~ V2.0 -
SiemensTotally Integrated Automation Portal (TIA Portal) V15.1 0 ~ * -
SiemensTotally Integrated Automation Portal (TIA Portal) V16 0 ~ * -
SiemensTotally Integrated Automation Portal (TIA Portal) V17 0 ~ V17 Update 8 -
SiemensTotally Integrated Automation Portal (TIA Portal) V18 0 ~ V18 Update 4 -
SiemensTotally Integrated Automation Portal (TIA Portal) V19 0 ~ V19 Update 2 -

II. Public POCs for CVE-2023-46280

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-46280

登录查看更多情报信息。

Same Patch Batch · Siemens · 2024-05-14 · 55 CVEs total

CVE-2024-3274110.0 CRITICALSiemens SIMATIC CN 4100 安全漏洞
CVE-2024-3020710.0 CRITICALSiemens 多款产品 安全漏洞
CVE-2024-327409.8 CRITICALSiemens SIMATIC CN 4100 信任管理问题漏洞
CVE-2024-279399.8 CRITICALSiemens RUGGEDCOM CROSSBOW 安全漏洞
CVE-2024-302099.6 CRITICALSiemens 多款产品 安全漏洞
CVE-2024-334999.1 CRITICALSiemens 多款产品 安全漏洞
CVE-2024-302068.8 HIGHSiemens 多款产品 安全漏洞
CVE-2024-279408.8 HIGHSiemens RUGGEDCOM CROSSBOW SQL注入漏洞
CVE-2024-279418.8 HIGHSiemens RUGGEDCOM CROSSBOW SQL注入漏洞
CVE-2024-347727.8 HIGHSiemens Solid Edge 缓冲区错误漏洞
CVE-2024-347717.8 HIGHSiemens Solid Edge 安全漏洞
CVE-2024-340867.8 HIGHSiemens 多款产品 缓冲区错误漏洞
CVE-2024-334897.8 HIGHSiemens Solid Edge 安全漏洞
CVE-2024-347737.8 HIGHSiemens Solid Edge 安全漏洞
CVE-2024-326397.8 HIGHSiemens Tecnomatix Plant Simulation 缓冲区错误漏洞
CVE-2024-326367.8 HIGHSiemens 多款产品 缓冲区错误漏洞
CVE-2024-326357.8 HIGHSiemens 多款产品 缓冲区错误漏洞
CVE-2024-320667.8 HIGHSiemens Parasolid 缓冲区错误漏洞
CVE-2024-320657.8 HIGHSiemens Parasolid 缓冲区错误漏洞
CVE-2024-334907.8 HIGHSiemens Solid Edge 缓冲区错误漏洞

Showing top 20 of 55 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2023-46280

No comments yet


Leave a comment