Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-30757

Опубликовано: 13 июн. 2023
Источник: nvd
CVSS3: 6.2
CVSS3: 5.5
EPSS Низкий

Описание

A vulnerability has been identified in Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal (TIA Portal) V15 (All versions), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All versions), Totally Integrated Automation Portal (TIA Portal) V19 (All versions), Totally Integrated Automation Portal (TIA Portal) V20 (All versions). The know-how protection feature in affected products does not properly update the encryption of existing program blocks when a project file is updated.

This could allow attackers with access to the project file to recover previous - yet unprotected - versions of the project without the knowledge of the know-how protection password.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:siemens:totally_integrated_automation_portal:14.0:*:*:*:*:*:*:*
cpe:2.3:a:siemens:totally_integrated_automation_portal:15:*:*:*:*:*:*:*
cpe:2.3:a:siemens:totally_integrated_automation_portal:15.1:-:*:*:*:*:*:*
cpe:2.3:a:siemens:totally_integrated_automation_portal:16:*:*:*:*:*:*:*
cpe:2.3:a:siemens:totally_integrated_automation_portal:17:*:*:*:*:*:*:*
cpe:2.3:a:siemens:totally_integrated_automation_portal:18:*:*:*:*:*:*:*

EPSS

Процентиль: 20%
0.00063
Низкий

6.2 Medium

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-693
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 6.2
github
больше 2 лет назад

A vulnerability has been identified in Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal (TIA Portal) V15 (All versions), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All versions). The know-how protection feature in affected products does not properly update the encryption of existing program blocks when a project file is updated. This could allow attackers with access to the project file to recover previous - yet unprotected - versions of the project without the knowledge of the know-how protection password.

CVSS3: 6.2
fstec
больше 2 лет назад

Уязвимость среды разработки программного обеспечения систем автоматизации технологических процессов Totally Integrated Automation Portal (Portal TIA), связанная с нарушением механизма защиты данных, позволяющая нарушителю восстановить незащищенную версию проекта

EPSS

Процентиль: 20%
0.00063
Низкий

6.2 Medium

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-693
NVD-CWE-noinfo