Know-How Protection Flaw in Siemens Totally Integrated Automation Portal Products
CVE-2023-30757

5.5MEDIUM

Summary

A critical vulnerability exists within Siemens Totally Integrated Automation Portal products that impacts the know-how protection feature. When project files are updated, the encryption for existing program blocks is not properly refreshed, permitting attackers with access to the project files to retrieve older, unprotected versions of the project. This unauthorized access occurs without requiring the know-how protection password, posing a significant risk to the confidentiality and integrity of sensitive automation data.

Affected Version(s)

Totally Integrated Automation Portal (TIA Portal) V14 0

Totally Integrated Automation Portal (TIA Portal) V15 0

Totally Integrated Automation Portal (TIA Portal) V15.1 0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.