{"Siemens: Multiple Products Affected by Deserialization Vulnerability","Siemens: Simatic Safety and Motion Control","Siemens: Sinamics Drive Technologies","Siemens: Simotion Safety","Siemens: TIA Portal Cloud"}
CVE-2023-32735

6.5MEDIUM

Key Information:

Summary

A vulnerability exists in various Siemens products, including SIMATIC STEP 7, SIMATIC WinCC, and other related applications, that fails to properly restrict .NET BinaryFormatter during the deserialization of hardware configuration profiles. This imperfection may lead to type confusion, enabling an attacker to execute arbitrary code within affected applications. This could result in unauthorized actions or data manipulation, posing a significant risk to system integrity and operations.

Affected Version(s)

SIMATIC STEP 7 Safety V16 0

SIMATIC STEP 7 Safety V17 0

SIMATIC STEP 7 Safety V18 0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.