CVE-2023-51438

A vulnerability has been identified in SIMATIC IPC1047E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPC647E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPC847E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows). In default installations of maxView Storage Manager where Redfish® server is configured for remote system management, a vulnerability has been identified that can provide unauthorized access.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:microchip:maxview_storage_manager:*:*:*:*:*:windows:*:*
OR cpe:2.3:h:siemens:simatic_ipc1047e:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc647e:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc847e:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:38

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 10.0
References () https://cert-portal.siemens.com/productcert/pdf/ssa-702935.pdf - Vendor Advisory () https://cert-portal.siemens.com/productcert/pdf/ssa-702935.pdf - Vendor Advisory

16 Jan 2024, 16:16

Type Values Removed Values Added
CPE cpe:2.3:h:siemens:simatic_ipc1047e:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc647e:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc847e:-:*:*:*:*:*:*:*
cpe:2.3:a:microchip:maxview_storage_manager:*:*:*:*:*:windows:*:*
First Time Siemens simatic Ipc647e
Siemens simatic Ipc1047e
Microchip maxview Storage Manager
Siemens simatic Ipc847e
Siemens
Microchip
CVSS v2 : unknown
v3 : 10.0
v2 : unknown
v3 : 9.8
References () https://cert-portal.siemens.com/productcert/pdf/ssa-702935.pdf - () https://cert-portal.siemens.com/productcert/pdf/ssa-702935.pdf - Vendor Advisory
CWE NVD-CWE-noinfo

09 Jan 2024, 14:01

Type Values Removed Values Added
Summary
  • (es) Se ha identificado una vulnerabilidad en SIMATIC IPC1047E (todas las versiones con maxView Storage Manager &lt; V4.14.00.26068 en Windows), SIMATIC IPC647E (todas las versiones con maxView Storage Manager &lt; V4.14.00.26068 en Windows), SIMATIC IPC847E (todas las versiones con maxView Storage Manager &lt; V4.14.00.26068 en Windows). En instalaciones predeterminadas de maxView Storage Manager donde el servidor Redfish® está configurado para la administración remota del sistema, se ha identificado una vulnerabilidad que puede proporcionar acceso no autorizado.

09 Jan 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-09 10:15

Updated : 2024-11-21 08:38


NVD link : CVE-2023-51438

Mitre link : CVE-2023-51438

CVE.ORG link : CVE-2023-51438


JSON object : View

Products Affected

siemens

  • simatic_ipc1047e
  • simatic_ipc647e
  • simatic_ipc847e

microchip

  • maxview_storage_manager
CWE
CWE-20

Improper Input Validation

NVD-CWE-noinfo