CVE-2023-51438

A vulnerability has been identified in SIMATIC IPC1047E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPC647E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPC847E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows). In default installations of maxView Storage Manager where Redfish® server is configured for remote system management, a vulnerability has been identified that can provide unauthorized access.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:microchip:maxview_storage_manager:*:*:*:*:*:windows:*:*
OR cpe:2.3:h:siemens:simatic_ipc1047e:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc647e:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc847e:-:*:*:*:*:*:*:*

History

16 Jan 2024, 16:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 10.0
v2 : unknown
v3 : 9.8
CPE cpe:2.3:h:siemens:simatic_ipc847e:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc1047e:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc647e:-:*:*:*:*:*:*:*
cpe:2.3:a:microchip:maxview_storage_manager:*:*:*:*:*:windows:*:*
CWE NVD-CWE-noinfo
First Time Siemens simatic Ipc847e
Microchip maxview Storage Manager
Siemens simatic Ipc647e
Siemens
Microchip
Siemens simatic Ipc1047e
References () https://cert-portal.siemens.com/productcert/pdf/ssa-702935.pdf - () https://cert-portal.siemens.com/productcert/pdf/ssa-702935.pdf - Vendor Advisory

09 Jan 2024, 14:01

Type Values Removed Values Added
Summary
  • (es) Se ha identificado una vulnerabilidad en SIMATIC IPC1047E (todas las versiones con maxView Storage Manager &lt; V4.14.00.26068 en Windows), SIMATIC IPC647E (todas las versiones con maxView Storage Manager &lt; V4.14.00.26068 en Windows), SIMATIC IPC847E (todas las versiones con maxView Storage Manager &lt; V4.14.00.26068 en Windows). En instalaciones predeterminadas de maxView Storage Manager donde el servidor Redfish® está configurado para la administración remota del sistema, se ha identificado una vulnerabilidad que puede proporcionar acceso no autorizado.

09 Jan 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-09 10:15

Updated : 2024-01-16 16:16


NVD link : CVE-2023-51438

Mitre link : CVE-2023-51438

CVE.ORG link : CVE-2023-51438


JSON object : View

Products Affected

microchip

  • maxview_storage_manager

siemens

  • simatic_ipc847e
  • simatic_ipc647e
  • simatic_ipc1047e
CWE
NVD-CWE-noinfo CWE-20

Improper Input Validation