CERT-In Vulnerability Note
CIVN-2023-0389
Information Disclosure Vulnerability in Siemens OPC UA Modeling Editor
Original Issue Date:December 26, 2023
Severity Rating: HIGH
Software Affected
- OPC UA Modelling Editor (SiOME): versions prior to V2.8
Overview
A vulnerability has been reported in Siemens OPC UA Modeling Editor, which could allow a remote attacker to obtain sensitive information.
Description
This vulnerability exists in Siemens OPC UA Modelling Editor (SiOME) due to improper handling of XML external entity (XXE) declarations by the affected software.
This issue could be exploited by a remote attacker by using a specially crafted XML content to read arbitrary files on the server.
Solution
- Update to V2.8 or later version
Vendor Information
https://cert-portal.siemens.com/productcert/pdf/ssa-197270.pdf
References
Siemens
https://cert-portal.siemens.com/productcert/pdf/ssa-197270.pdf
https://support.industry.siemens.com/cs/document/109755133/siemens-opc-ua-modeling-editor-(siome)?dti=0&lc=en-US
https://cert-portal.siemens.com/operational-guidelines-industrial-security.pdf
CISA
https://www.cisa.gov/news-events/ics-advisories/icsa-23-320-07
CVE Name
CVE-2023-46590
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|