Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-28832


A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2.0 < V2.1). The web based management of affected devices does not properly validate user input, making it susceptible to command injection. This could allow an authenticated privileged remote attacker to execute arbitrary code with root privileges.


Published

2023-05-09T13:15:17.373

Last Modified

2024-11-21T07:56:06.930

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

Weaknesses
  • Type: Primary
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System siemens 6gk1411-1ac00_firmware 2.0 Yes
Hardware siemens 6gk1411-1ac00 - No
Operating System siemens 6gk1411-5ac00_firmware 2.0 Yes
Hardware siemens 6gk1411-5ac00 - No

References