CVE-2023-51438

A vulnerability has been identified in SIMATIC IPC1047E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPC647E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPC847E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows). In default installations of maxView Storage Manager where Redfish® server is configured for remote system management, a vulnerability has been identified that can provide unauthorized access.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:microchip:maxview_storage_manager:*:*:*:*:*:windows:*:*
OR cpe:2.3:h:siemens:simatic_ipc1047e:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc647e:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc847e:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:38

Type Values Removed Values Added
References () https://cert-portal.siemens.com/productcert/pdf/ssa-702935.pdf - Vendor Advisory () https://cert-portal.siemens.com/productcert/pdf/ssa-702935.pdf - Vendor Advisory
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 10.0

16 Jan 2024, 16:16

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CPE cpe:2.3:h:siemens:simatic_ipc847e:-:*:*:*:*:*:*:*
cpe:2.3:a:microchip:maxview_storage_manager:*:*:*:*:*:windows:*:*
cpe:2.3:h:siemens:simatic_ipc1047e:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc647e:-:*:*:*:*:*:*:*
First Time Siemens simatic Ipc847e
Siemens simatic Ipc647e
Microchip
Microchip maxview Storage Manager
Siemens simatic Ipc1047e
Siemens
References () https://cert-portal.siemens.com/productcert/pdf/ssa-702935.pdf - () https://cert-portal.siemens.com/productcert/pdf/ssa-702935.pdf - Vendor Advisory
CVSS v2 : unknown
v3 : 10.0
v2 : unknown
v3 : 9.8

09 Jan 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-09 10:15

Updated : 2024-11-21 08:38


NVD link : CVE-2023-51438

Mitre link : CVE-2023-51438

CVE.ORG link : CVE-2023-51438


JSON object : View

Products Affected

siemens

  • simatic_ipc847e
  • simatic_ipc647e
  • simatic_ipc1047e

microchip

  • maxview_storage_manager
CWE
CWE-20

Improper Input Validation

NVD-CWE-noinfo