Path Traversal Flaw in SIMATIC Cloud Connect Products by Siemens
CVE-2023-29104

6MEDIUM

Key Information:

Summary

A vulnerability has been detected in specific versions of Siemens SIMATIC Cloud Connect 7 CC712 and CC716. This path traversal vulnerability affects the upload feature in the web-based management interface, potentially granting an authenticated privileged remote attacker the ability to overwrite files accessible to the Linux user ccuser. Additionally, the flaw allows for the unauthorized download of any files that the ccuser can read. This security issue poses significant risks to data integrity and confidentiality.

Affected Version(s)

SIMATIC Cloud Connect 7 CC712 All versions >= V2.0 < V2.1

SIMATIC Cloud Connect 7 CC716 All versions >= V2.0 < V2.1

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.