Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-26293


A vulnerability has been identified in Totally Integrated Automation Portal (TIA Portal) V15 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All versions < V16 Update 7), Totally Integrated Automation Portal (TIA Portal) V17 (All versions < V17 Update 6), Totally Integrated Automation Portal (TIA Portal) V18 (All versions < V18 Update 1). Affected products contain a path traversal vulnerability that could allow the creation or overwrite of arbitrary files in the engineering system. If the user is tricked to open a malicious PC system configuration file, an attacker could exploit this vulnerability to achieve arbitrary code execution.


Published

2023-04-11T10:15:18.157

Last Modified

2024-11-21T07:51:04.510

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.3 (HIGH)

Weaknesses
  • Type: Primary
    CWE-20
  • Type: Secondary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application siemens tia_portal 15 Yes
Application siemens tia_portal 16 Yes
Application siemens tia_portal 17 Yes
Application siemens tia_portal 17 Yes
Application siemens tia_portal 17 Yes
Application siemens tia_portal 17 Yes
Application siemens tia_portal 17 Yes
Application siemens tia_portal 17 Yes
Application siemens tia_portal 18 Yes

References