CERT-In Vulnerability Note
CIVN-2023-0385
Multiple Vulnerabilities in Siemens SIMATIC PCS neo
Original Issue Date:December 22, 2023
Severity Rating: HIGH
Systems Affected
- SIMATIC PCS neo: versions prior to 4.1
Overview
Multiple vulnerabilities have been reported in Siemens SIMATIC PCS neo, which could allow an attacker to upload additional documents, trigger unwanted behavior or perform SQL injection or XSS attacks on the target application.
Description
1. Missing Authentication for Critical Function vulnerability
(
CVE-2023-46096
)
This vulnerability is due to the PUD Manager of affected products does not properly authenticate users in the PUD Manager web service. This could allow an unauthenticated adjacent attacker to generate a privileged token and upload additional documents.
2. SQL Injection vulnerability
(
CVE-2023-46097
)
This vulnerability is due to the PUD Manager of affected products does not properly neutralize user provided inputs. This could allow an authenticated adjacent attacker to execute SQL statements in the underlying database.
3. Permissive Cross-Domain Policy with Untrusted Domains vulnerability
(
CVE-2023-46098
)
This vulnerability exists in the information server of the affected products. While accessing the Information server; it uses an overly permissive CORS policy, which could allow an attacker to trick a legitimate user to trigger unwanted behavior.
4. Administration Console Cross-Site Scripting vulnerability
(
CVE-2023-46099
)
This vulnerability exists in the Administration Console of the affected product. An attacker could exploit this issue to inject Javascript code into the application that would be later executed by another legitimate user.
Solution
Update to SIMATIC PCS neo version 4.1 or later.
https://cert-portal.siemens.com/productcert/html/ssa-456933.html
Vendor Information
Siemens:
https://cert-portal.siemens.com/productcert/html/ssa-456933.html
References
Siemens:
https://cert-portal.siemens.com/productcert/html/ssa-456933.html
CISA
https://www.cisa.gov/news-events/ics-advisories/icsa-23-320-06
CVE Name
CVE-2023-46096
CVE-2023-46097
CVE-2023-46098
CVE-2023-46099
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|