Improper Authentication in SIMATIC PCS neo by Siemens
CVE-2023-46096
6.5MEDIUM
What is CVE-2023-46096?
A security issue has been detected in SIMATIC PCS neo, where the PUD Manager web service fails to properly authenticate users. This vulnerability may allow an unauthorized attacker within the adjacent network to produce a privileged token, which could facilitate the upload of additional documents without the necessary permissions. It emphasizes the importance of robust authentication measures to protect against unauthorized access and potential data breaches.
Affected Version(s)
SIMATIC PCS neo All versions < V4.1