SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-23588

A vulnerability has been identified in SIMATIC IPC1047 (All versions), SIMATIC IPC1047E (All versions with maxView Storage Manager < 4.09.00.25611 on Windows), SIMATIC IPC647D (All versions), SIMATIC IPC647E (All versions with maxView Storage Manager <…

MEDIUM 6.3EPSS 0.09%

Does this matter?

Lower severity and a low EPSS score (0.09%). Track it; it rarely justifies an emergency change on its own.

Description

A vulnerability has been identified in SIMATIC IPC1047 (All versions), SIMATIC IPC1047E (All versions with maxView Storage Manager < 4.09.00.25611 on Windows), SIMATIC IPC647D (All versions), SIMATIC IPC647E (All versions with maxView Storage Manager < 4.09.00.25611 on Windows), SIMATIC IPC847D (All versions), SIMATIC IPC847E (All versions with maxView Storage Manager < 4.09.00.25611 on Windows). The Adaptec Maxview application on affected devices is using a non-unique TLS certificate across installations to protect the communication from the local browser to the local application. A local attacker may use this key to decrypt intercepted local traffic between the browser and the application and could perform a man-in-the-middle attack in order to modify data in transit.

CVSS 3.1
6.3 MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS
0.09% probability · 1th percentile
CISA KEV
Not listed
Weakness
CWE-200, CWE-295
Affected
siemens/simatic ipc647d firmware · siemens/simatic ipc847d firmware · siemens/simatic ipc1047 firmware · microchip/maxview storage manager
Source
productcert@siemens.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.