CVE-2023-46280
Siemens · published 2024-05-14
Source record Collected from the National Vulnerability Database (NVD)
Description
Description by Siemens AG via the CVE Program.
A vulnerability has been identified in Security Configuration Tool (SCT) (All versions), SIMATIC Automation Tool (All versions < V5.0 SP2), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 Upd5), SIMATIC NET PC Software V16 (All versions < V16 Update 8), SIMATIC NET PC Software V17 (All versions), SIMATIC NET PC Software V18 (All versions < V18 SP1), SIMATIC NET PC Software V19 (All versions < V19 Update 2), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC PDM V9.2 (All versions < V9.2 SP2 Upd3), SIMATIC Route Control V9.1 (All versions < V9.1 SP2 Upd3), SIMATIC S7-PCT (All versions < V3.5 SP3 Update 6), SIMATIC STEP 7 V5 (All versions < V5.7 SP3), SIMATIC WinCC OA V3.17 (All versions), SIMATIC WinCC OA V3.18 (All versions < V3.18 P025), SIMATIC WinCC OA V3.19 (All versions < V3.19 P010), SIMATIC WinCC Runtime Advanced (All versions < V17 Update 8), SIMATIC WinCC Runtime Professional V16 (All versions < V16 Update 6), SIMATIC WinCC Runtime Professional V17 (All versions < V17 Update 8), SIMATIC WinCC Runtime Professional V18 (All versions < V18 Update 4), SIMATIC WinCC Runtime Professional V19 (All versions < V19 Update 2), SIMATIC WinCC V7.4 (All versions), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 17), SIMATIC WinCC V8.0 (All versions < V8.0 Update 5), SINAMICS Startdrive (All versions < V19 SP1), SINEC NMS (All versions < V3.0), SINUMERIK ONE virtual (All versions < V6.23), SINUMERIK PLC Programming Tool (All versions < V3.3.12), TIA Portal Cloud Connector (All versions < V2.0), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions < V17 Update 8), Totally Integrated Automation Portal (TIA Portal) V18 (All versions < V18 Update 4), Totally Integrated Automation Portal (TIA Portal) V19 (All versions < V19 Update 2), SINEC NMS (All versions < V3.0 SP1). The affected applications contain an out of bounds read vulnerability. This could allow an attacker to cause a Blue Screen of Death (BSOD) crash of the underlying Windows kernel.
Status at the source
- NVD status: Deferred — NVD has not analysed this CVE.
Affected products, as the source lists them
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Security Configuration Tool (SCT) | 0 – before *: affected |
| Siemens | SIMATIC Automation Tool | 0 – before V5.0 SP2: affected |
| Siemens | SIMATIC BATCH V9.1 | 0 – before V9.1 SP2 Upd5: affected |
| Siemens | SIMATIC NET PC Software V16 | 0 – before V16 Update 8: affected |
| Siemens | SIMATIC NET PC Software V17 | 0 – before *: affected |
| Siemens | SIMATIC NET PC Software V18 | 0 – before V18 SP1: affected |
| Siemens | SIMATIC NET PC Software V19 | 0 – before V19 Update 2: affected |
| Siemens | SIMATIC PCS 7 V9.1 | 0 – before V9.1 SP2 UC05: affected |
| Siemens | SIMATIC PDM V9.2 | 0 – before V9.2 SP2 Upd3: affected |
| Siemens | SIMATIC Route Control V9.1 | 0 – before V9.1 SP2 Upd3: affected |
| Siemens | SIMATIC S7-PCT | 0 – before V3.5 SP3 Update 6: affected |
| Siemens | SIMATIC STEP 7 V5 | 0 – before V5.7 SP3: affected |
| Siemens | SIMATIC WinCC OA V3.17 | 0 – before *: affected |
| Siemens | SIMATIC WinCC OA V3.18 | 0 – before V3.18 P025: affected |
| Siemens | SIMATIC WinCC OA V3.19 | 0 – before V3.19 P010: affected |
| Siemens | SIMATIC WinCC Runtime Advanced | 0 – before V17 Update 8: affected |
| Siemens | SIMATIC WinCC Runtime Professional V16 | 0 – before V16 Update 6: affected |
| Siemens | SIMATIC WinCC Runtime Professional V17 | 0 – before V17 Update 8: affected |
| Siemens | SIMATIC WinCC Runtime Professional V18 | 0 – before V18 Update 4: affected |
| Siemens | SIMATIC WinCC Runtime Professional V19 | 0 – before V19 Update 2: affected |
| Siemens | SIMATIC WinCC V7.4 | 0 – before *: affected |
| Siemens | SIMATIC WinCC V7.5 | 0 – before V7.5 SP2 Update 17: affected |
| Siemens | SIMATIC WinCC V8.0 | 0 – before V8.0 Update 5: affected |
| Siemens | SINAMICS Startdrive | 0 – before V19 SP1: affected |
| Siemens | SINEC NMS | 0 – before V3.0: affected |
| Siemens | SINUMERIK ONE virtual | 0 – before V6.23: affected |
| Siemens | SINUMERIK PLC Programming Tool | 0 – before V3.3.12: affected |
| Siemens | TIA Portal Cloud Connector | 0 – before V2.0: affected |
| Siemens | Totally Integrated Automation Portal (TIA Portal) V15.1 | 0 – before *: affected |
| Siemens | Totally Integrated Automation Portal (TIA Portal) V16 | 0 – before *: affected |
| Siemens | Totally Integrated Automation Portal (TIA Portal) V17 | 0 – before V17 Update 8: affected |
| Siemens | Totally Integrated Automation Portal (TIA Portal) V18 | 0 – before V18 Update 4: affected |
| Siemens | Totally Integrated Automation Portal (TIA Portal) V19 | 0 – before V19 Update 2: affected |
| Siemens | SINEC NMS | 0 – before V3.0 SP1: affected |
DeSpy has not checked any unit, hardware revision or firmware. A product missing here is not a statement that it is unaffected.
Scores, as their sources published them
- CVSS 4.0: 8.2 HIGH — as published by Siemens AG (Secondary)
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - CVSS 3.1: 6.5 MEDIUM — as published by Siemens AG (Secondary)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H - SSVC — CISA's assessment (SSVC 2.0.3, CISA Coordinator): Exploitation: none · Automatable: no · Technical impact: partial
DeSpy does not score records. These are the sources' own values.
Weaknesses
Sources
References the source lists
- https://cert-portal.siemens.com/productcert/html/ssa-331112.html
- https://cert-portal.siemens.com/productcert/html/ssa-784301.html
- https://cert-portal.siemens.com/productcert/html/ssa-962515.html
- https://cert-portal.siemens.com/productcert/html/ssa-962515.html
Source dates: published 2024-05-14, last changed 2026-06-17. DeSpy's copy of this version is dated 2026-09-28.
This product uses the NVD API but is not endorsed or certified by the NVD.
CVE records: Copyright © 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation.
CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE™). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.
CISA's Known Exploited Vulnerabilities catalog and CISA Vulnrichment data are CC0 1.0. CISA advisories are shown with the TLP label their document carries. No endorsement by CISA, DHS, NIST or MITRE is stated or implied.