← Security Alerts

CVE-2023-46280

Siemens · published 2024-05-14

Source record Collected from the National Vulnerability Database (NVD)

Description

Description by Siemens AG via the CVE Program.

A vulnerability has been identified in Security Configuration Tool (SCT) (All versions), SIMATIC Automation Tool (All versions < V5.0 SP2), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 Upd5), SIMATIC NET PC Software V16 (All versions < V16 Update 8), SIMATIC NET PC Software V17 (All versions), SIMATIC NET PC Software V18 (All versions < V18 SP1), SIMATIC NET PC Software V19 (All versions < V19 Update 2), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC PDM V9.2 (All versions < V9.2 SP2 Upd3), SIMATIC Route Control V9.1 (All versions < V9.1 SP2 Upd3), SIMATIC S7-PCT (All versions < V3.5 SP3 Update 6), SIMATIC STEP 7 V5 (All versions < V5.7 SP3), SIMATIC WinCC OA V3.17 (All versions), SIMATIC WinCC OA V3.18 (All versions < V3.18 P025), SIMATIC WinCC OA V3.19 (All versions < V3.19 P010), SIMATIC WinCC Runtime Advanced (All versions < V17 Update 8), SIMATIC WinCC Runtime Professional V16 (All versions < V16 Update 6), SIMATIC WinCC Runtime Professional V17 (All versions < V17 Update 8), SIMATIC WinCC Runtime Professional V18 (All versions < V18 Update 4), SIMATIC WinCC Runtime Professional V19 (All versions < V19 Update 2), SIMATIC WinCC V7.4 (All versions), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 17), SIMATIC WinCC V8.0 (All versions < V8.0 Update 5), SINAMICS Startdrive (All versions < V19 SP1), SINEC NMS (All versions < V3.0), SINUMERIK ONE virtual (All versions < V6.23), SINUMERIK PLC Programming Tool (All versions < V3.3.12), TIA Portal Cloud Connector (All versions < V2.0), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions < V17 Update 8), Totally Integrated Automation Portal (TIA Portal) V18 (All versions < V18 Update 4), Totally Integrated Automation Portal (TIA Portal) V19 (All versions < V19 Update 2), SINEC NMS (All versions < V3.0 SP1). The affected applications contain an out of bounds read vulnerability. This could allow an attacker to cause a Blue Screen of Death (BSOD) crash of the underlying Windows kernel.

Status at the source

Affected products, as the source lists them

VendorProductVersions
SiemensSecurity Configuration Tool (SCT)0 – before *: affected
SiemensSIMATIC Automation Tool0 – before V5.0 SP2: affected
SiemensSIMATIC BATCH V9.10 – before V9.1 SP2 Upd5: affected
SiemensSIMATIC NET PC Software V160 – before V16 Update 8: affected
SiemensSIMATIC NET PC Software V170 – before *: affected
SiemensSIMATIC NET PC Software V180 – before V18 SP1: affected
SiemensSIMATIC NET PC Software V190 – before V19 Update 2: affected
SiemensSIMATIC PCS 7 V9.10 – before V9.1 SP2 UC05: affected
SiemensSIMATIC PDM V9.20 – before V9.2 SP2 Upd3: affected
SiemensSIMATIC Route Control V9.10 – before V9.1 SP2 Upd3: affected
SiemensSIMATIC S7-PCT0 – before V3.5 SP3 Update 6: affected
SiemensSIMATIC STEP 7 V50 – before V5.7 SP3: affected
SiemensSIMATIC WinCC OA V3.170 – before *: affected
SiemensSIMATIC WinCC OA V3.180 – before V3.18 P025: affected
SiemensSIMATIC WinCC OA V3.190 – before V3.19 P010: affected
SiemensSIMATIC WinCC Runtime Advanced0 – before V17 Update 8: affected
SiemensSIMATIC WinCC Runtime Professional V160 – before V16 Update 6: affected
SiemensSIMATIC WinCC Runtime Professional V170 – before V17 Update 8: affected
SiemensSIMATIC WinCC Runtime Professional V180 – before V18 Update 4: affected
SiemensSIMATIC WinCC Runtime Professional V190 – before V19 Update 2: affected
SiemensSIMATIC WinCC V7.40 – before *: affected
SiemensSIMATIC WinCC V7.50 – before V7.5 SP2 Update 17: affected
SiemensSIMATIC WinCC V8.00 – before V8.0 Update 5: affected
SiemensSINAMICS Startdrive0 – before V19 SP1: affected
SiemensSINEC NMS0 – before V3.0: affected
SiemensSINUMERIK ONE virtual0 – before V6.23: affected
SiemensSINUMERIK PLC Programming Tool0 – before V3.3.12: affected
SiemensTIA Portal Cloud Connector0 – before V2.0: affected
SiemensTotally Integrated Automation Portal (TIA Portal) V15.10 – before *: affected
SiemensTotally Integrated Automation Portal (TIA Portal) V160 – before *: affected
SiemensTotally Integrated Automation Portal (TIA Portal) V170 – before V17 Update 8: affected
SiemensTotally Integrated Automation Portal (TIA Portal) V180 – before V18 Update 4: affected
SiemensTotally Integrated Automation Portal (TIA Portal) V190 – before V19 Update 2: affected
SiemensSINEC NMS0 – before V3.0 SP1: affected

DeSpy has not checked any unit, hardware revision or firmware. A product missing here is not a statement that it is unaffected.

Scores, as their sources published them

DeSpy does not score records. These are the sources' own values.

Weaknesses

CWE-125

Sources

References the source lists

Source dates: published 2024-05-14, last changed 2026-06-17. DeSpy's copy of this version is dated 2026-09-28.

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE records: Copyright © 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation.

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE™). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

CISA's Known Exploited Vulnerabilities catalog and CISA Vulnrichment data are CC0 1.0. CISA advisories are shown with the TLP label their document carries. No endorsement by CISA, DHS, NIST or MITRE is stated or implied.

Scope, sources and licences →