CVE-2023-23588
Published on: Not Yet Published
Last Modified on: 04/19/2023 08:00:00 PM UTC
Certain versions of Maxview Storage Manager from Microsemi contain the following vulnerability:
A vulnerability has been identified in SIMATIC IPC1047 (All versions), SIMATIC IPC1047E (All versions with maxView Storage Manager < 4.09.00.25611 on Windows), SIMATIC IPC647D (All versions), SIMATIC IPC647E (All versions with maxView Storage Manager < 4.09.00.25611 on Windows), SIMATIC IPC847D (All versions), SIMATIC IPC847E (All versions with maxView Storage Manager < 4.09.00.25611 on Windows). The Adaptec Maxview application on affected devices is using a non-unique TLS certificate across installations to protect the communication from the local browser to the local application. A local attacker may use this key to decrypt intercepted local traffic between the browser and the application and could perform a man-in-the-middle attack in order to modify data in transit.
- CVE-2023-23588 has been assigned by
productc[email protected] to track the vulnerability - currently rated as MEDIUM severity.
CVSS3 Score: 6.3 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | HIGH | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Vendor Advisory cert-portal.siemens.com application/pdf |
![]() |
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Microsemi | Maxview Storage Manager | All | All | All | All |
Hardware
| Siemens | Simatic Ipc1047 | - | All | All | All |
Hardware
| Siemens | Simatic Ipc1047e | - | All | All | All |
Operating System | Siemens | Simatic Ipc1047 Firmware | All | All | All | All |
Hardware
| Siemens | Simatic Ipc647d | - | All | All | All |
Operating System | Siemens | Simatic Ipc647d Firmware | All | All | All | All |
Hardware
| Siemens | Simatic Ipc647e | - | All | All | All |
Hardware
| Siemens | Simatic Ipc847d | - | All | All | All |
Operating System | Siemens | Simatic Ipc847d Firmware | All | All | All | All |
Hardware
| Siemens | Simatic Ipc847e | - | All | All | All |
- cpe:2.3:a:microsemi:maxview_storage_manager:*:*:*:*:*:windows:*:*:
- cpe:2.3:h:siemens:simatic_ipc1047:-:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:simatic_ipc1047e:-:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:simatic_ipc1047_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:simatic_ipc647d:-:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:simatic_ipc647d_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:simatic_ipc647e:-:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:simatic_ipc847d:-:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:simatic_ipc847d_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:simatic_ipc847e:-:*:*:*:*:*:*:*:
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2023-23588 : A vulnerability has been identified in SIMATIC IPC1047 All versions , SIMATIC IPC1047E All versi… twitter.com/i/web/status/1… | 2023-04-11 10:03:24 |