Debug Access Vulnerability in Siemens SIMOTION Products
CVE-2023-27465
4.6MEDIUM
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 13 June 2023
Summary
A security vulnerability has been discovered in various Siemens SIMOTION products that, when configured with a low security level, compromises access controls. Specifically, this flaw does not adequately secure certain services vital for debugging, enabling an unauthenticated attacker to retrieve sensitive technology object configurations from the affected devices. This raises significant security concerns for operational environments utilizing these systems.
Affected Version(s)
SIMOTION C240 All versions >= V5.4 < V5.5 SP1
SIMOTION C240 PN All versions >= V5.4 < V5.5 SP1
SIMOTION D410-2 DP All versions >= V5.4 < V5.5 SP1
References
CVSS V3.1
Score:
4.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved