VulnerabilityModified
CVE-2023-44373
This could allow an authenticated remote attacker with administrative privileges to inject code or spawn a system root shell.
CRITICAL 9.4EPSS 1.34%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.34%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject code or spawn a system root shell. Follow-up of CVE-2022-36323.
- CVSS 4.0
- 9.4 CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 1.34% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74
- Affected
- siemens/6gk5205-3bb00-2ab2 firmware · siemens/6gk5205-3bb00-2tb2 firmware · siemens/6gk5205-3bd00-2tb2 firmware · siemens/6gk5205-3bd00-2ab2 firmware · siemens/6gk5205-3bf00-2tb2 firmware · siemens/6gk5205-3bf00-2ab2 firmware · siemens/6gk5208-0ba00-2tb2 firmware · siemens/6gk5208-0ba00-2ab2 firmware · siemens/6gk5213-3bd00-2tb2 firmware · siemens/6gk5213-3bd00-2ab2 firmware · siemens/6gk5213-3bb00-2tb2 firmware · siemens/6gk5213-3bb00-2ab2 firmware · siemens/6gk5213-3bf00-2tb2 firmware · siemens/6gk5213-3bf00-2ab2 firmware · siemens/6gk5216-0ba00-2tb2 firmware · siemens/6gk5216-0ba00-2ab2 firmware · siemens/6gk5206-2bd00-2ac2 firmware · siemens/6gk5206-2bb00-2ac2 firmware · siemens/6gk5206-2rs00-2ac2 firmware · siemens/6gk5206-2rs00-5ac2 firmware · +40 more
- Source
- productcert@siemens.com
References
- https://cert-portal.siemens.com/productcert/html/ssa-019200.html
- https://cert-portal.siemens.com/productcert/html/ssa-180704.html
- https://cert-portal.siemens.com/productcert/html/ssa-602936.html
- https://cert-portal.siemens.com/productcert/html/ssa-690517.html
- https://cert-portal.siemens.com/productcert/html/ssa-699386.html
- https://cert-portal.siemens.com/productcert/html/ssa-721642.html
- https://cert-portal.siemens.com/productcert/pdf/ssa-180704.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-699386.pdfVendor Advisory
- https://cert-portal.siemens.com/productcert/html/ssa-180704.html
- https://cert-portal.siemens.com/productcert/html/ssa-602936.html
- https://cert-portal.siemens.com/productcert/html/ssa-690517.html
- https://cert-portal.siemens.com/productcert/html/ssa-699386.html
- https://cert-portal.siemens.com/productcert/pdf/ssa-180704.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-699386.pdfVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.