{"Siemens: Multiple Products Affected by Deserialization Vulnerability","Siemens: Simatic Safety and Motion Control","Siemens: Sinamics Drive Technologies","Siemens: Simotion Safety","Siemens: TIA Portal Cloud"}
CVE-2023-32735
7HIGH
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 9 July 2024
What is CVE-2023-32735?
A vulnerability exists in various Siemens products, including SIMATIC STEP 7, SIMATIC WinCC, and other related applications, that fails to properly restrict .NET BinaryFormatter during the deserialization of hardware configuration profiles. This imperfection may lead to type confusion, enabling an attacker to execute arbitrary code within affected applications. This could result in unauthorized actions or data manipulation, posing a significant risk to system integrity and operations.
Affected Version(s)
SIMATIC STEP 7 Safety V16 0
SIMATIC STEP 7 Safety V17 0
SIMATIC STEP 7 Safety V18 0