CVE-2023-26293
Summary
| CVE | CVE-2023-26293 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-04-11 10:15:00 UTC |
| Updated | 2024-02-01 15:19:00 UTC |
| Description | A vulnerability has been identified in Totally Integrated Automation Portal (TIA Portal) V15 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions < V17 Update 6), Totally Integrated Automation Portal (TIA Portal) V18 (All versions < V18 Update 1). Affected products contain a path traversal vulnerability that could allow the creation or overwrite of arbitrary files in the engineering system. If the user is tricked to open a malicious PC system configuration file, an attacker could exploit this vulnerability to achieve arbitrary code execution. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Siemens | Tia Portal | 15 | All | All | All |
| Application | Siemens | Tia Portal | 16 | All | All | All |
| Application | Siemens | Tia Portal | 17 | All | All | All |
| Application | Siemens | Tia Portal | 17 | - | All | All |
| Application | Siemens | Tia Portal | 17 | update1 | All | All |
| Application | Siemens | Tia Portal | 17 | update2 | All | All |
| Application | Siemens | Tia Portal | 17 | update3 | All | All |
| Application | Siemens | Tia Portal | 17 | update4 | All | All |
| Application | Siemens | Tia Portal | 17 | update5 | All | All |
| Application | Siemens | Tia Portal | 18 | - | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| cert-portal.siemens.com/productcert/pdf/ssa-116924.pdf | MISC | cert-portal.siemens.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.