Know-How Protection Flaw in Siemens Totally Integrated Automation Portal Products
CVE-2023-30757
5.5MEDIUM
Key Information:
Summary
A critical vulnerability exists within Siemens Totally Integrated Automation Portal products that impacts the know-how protection feature. When project files are updated, the encryption for existing program blocks is not properly refreshed, permitting attackers with access to the project files to retrieve older, unprotected versions of the project. This unauthorized access occurs without requiring the know-how protection password, posing a significant risk to the confidentiality and integrity of sensitive automation data.
Affected Version(s)
Totally Integrated Automation Portal (TIA Portal) V14 0
Totally Integrated Automation Portal (TIA Portal) V15 0
Totally Integrated Automation Portal (TIA Portal) V15.1 0
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved