Beveiligingsadvies

CVE-2023-28832

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2023-05-09 11:51:28
Laatst bijgewerkt 2025-01-28 18:42:40
Toegewezen door siemens
CVSS-score 7.2
Status PUBLISHED

Beschrijving

A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2.0 < V2.1). The web based management of affected devices does not properly validate user input, making it susceptible to command injection. This could allow an authenticated privileged remote attacker to execute arbitrary code with root privileges.