Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-28829


A vulnerability has been identified in SIMATIC NET PC Software V14 (All versions), SIMATIC NET PC Software V15 (All versions), SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS 7 V9.1 (All versions), SIMATIC WinCC (All versions < V8.0), SINAUT Software ST7sc (All versions). Before SIMATIC WinCC V8, legacy OPC services (OPC DA (Data Access), OPC HDA (Historical Data Access), and OPC AE (Alarms & Events)) were used per default. These services were designed on top of the Windows ActiveX and DCOM mechanisms and do not implement state-of-the-art security mechanisms for authentication and encryption of contents.


Published

2023-06-13T09:15:16.707

Last Modified

2024-11-21T07:56:06.343

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 3.9 (LOW)

Weaknesses
  • Type: Secondary
    CWE-477
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application siemens simatic_net_pc_software 14.0 Yes
Application siemens simatic_net_pc_software 15.0 Yes
Application siemens simatic_pcs_7 8.2 Yes
Application siemens simatic_pcs_7 9.0 Yes
Application siemens simatic_pcs_7 9.1 Yes
Application siemens simatic_wincc < 8.0 Yes
Application siemens sinaut_st7sc * Yes

References