CORS Misconfiguration in Siemens Web Interfaces
CVE-2023-46281
8.8HIGH
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 12 December 2023
What is CVE-2023-46281?
A vulnerability exists in the web interfaces of several Siemens products, where an overly permissive CORS policy could allow an attacker to exploit this misconfiguration. By manipulating CORS settings, an attacker could deceive legitimate users into triggering unintended actions, which may compromise the security of the user's session or expose sensitive data.
Affected Version(s)
Opcenter Execution Foundation 0
Opcenter Quality 0
SIMATIC PCS neo 0