Stored Cross-Site Scripting Flaw in SIMATIC PCS neo by Siemens
CVE-2023-46099

4.8MEDIUM

Key Information:

Vendor
Siemens
Vendor
CVE Published:
14 November 2023

Summary

A stored cross-site scripting vulnerability has been discovered in the Administration Console of SIMATIC PCS neo. This security flaw affects all versions prior to V4.1 and allows an attacker with elevated privileges to inject malicious JavaScript code into the application. The injected code can then be executed by another user, potentially compromising sensitive information and endangering system integrity.

Affected Version(s)

SIMATIC PCS neo All versions < V4.1

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.