CVE-2023-46284

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Dec 12, 2023
Updated: Aug 13, 2024
CWE ID 787
CWE ID 120

Summary

CVE-2023-46284 is a newly identified vulnerability affecting multiple Siemens automation software versions, including Opcenter Quality, SIMATIC PCS neo, SINEC NMS, and various TIA Portal editions. The issue involves an out-of-bounds write vulnerability on ports 4002/tcp and 4004/tcp. Malicious actors can exploit this flaw to crash the affected applications, leading to potential downtime and service disruptions. The automatic restart feature of these applications mitigates the immediate impact, but repeated attacks could pose significant risks. Affected users are advised to update their software to the latest patched versions as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Siemens TIA Portal

Affected Vendors

  • Siemens AG