Lucene search

K
nvd[email protected]NVD:CVE-2023-29103
HistoryMay 09, 2023 - 1:15 p.m.

CVE-2023-29103

2023-05-0913:15:17
CWE-259
web.nvd.nist.gov
6
vulnerability
hard-coded password
protected data
authenticated attacker
diagnostic files

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

4.7

Confidence

High

EPSS

0.001

Percentile

17.5%

A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC712 (All versions < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions < V2.1). The affected device uses a hard-coded password to protect the diagnostic files. This could allow an authenticated attacker to access protected data.

Affected configurations

Nvd
Node
siemens6gk1411-1ac00_firmwareRange<2.1
AND
siemens6gk1411-1ac00Match-
Node
siemens6gk1411-5ac00_firmwareRange<2.1
AND
siemens6gk1411-5ac00Match-
VendorProductVersionCPE
siemens6gk1411-1ac00_firmware*cpe:2.3:o:siemens:6gk1411-1ac00_firmware:*:*:*:*:*:*:*:*
siemens6gk1411-1ac00-cpe:2.3:h:siemens:6gk1411-1ac00:-:*:*:*:*:*:*:*
siemens6gk1411-5ac00_firmware*cpe:2.3:o:siemens:6gk1411-5ac00_firmware:*:*:*:*:*:*:*:*
siemens6gk1411-5ac00-cpe:2.3:h:siemens:6gk1411-5ac00:-:*:*:*:*:*:*:*

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

4.7

Confidence

High

EPSS

0.001

Percentile

17.5%

Related for NVD:CVE-2023-29103