CVE Feed

    Dashboard / CVE / CVE-2023-28829

    CVE-2023-28829

    A vulnerability has been identified in SIMATIC NET PC Software V14 (All versions), SIMATIC NET PC Software V15 (All versions), SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS 7 V9.1 (All versions), SIMATIC WinCC (All versions < V8.0), SINAUT Software ST7sc (All versions). Before SIMATIC WinCC V8, legacy OPC services (OPC DA (Data Access), OPC HDA (Historical Data Access), and OPC AE (Alarms & Events)) were used per default. These services were designed on top of the Windows ActiveX and DCOM mechanisms and do not implement state-of-the-art security mechanisms for authentication and encryption of contents.

    Published:Jun 13, 2023
    Last Modified:Jan 3, 2025
    EPS:Jun 13, 2023
    EPSS Score:0.00072
    CVSS Score:3.9

    Affected Products

    Vendor
    Siemens
    Product
    Simatic Net Pc Software
    Vendor
    Siemens
    Product
    Simatic Pcs 7
    Vendor
    Siemens
    Product
    Simatic Wincc
    Vendor
    Siemens
    Product
    Sinaut St7sc

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High