CVE-2023-46099
https://notcve.org/view.php?id=CVE-2023-46099
A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). There is a stored cross-site scripting vulnerability in the Administration Console of the affected product, that could allow an attacker with high privileges to inject Javascript code into the application that is later executed by another legitimate user. Se ha identificado una vulnerabilidad en SIMATIC PCS neo (todas las versiones < V4.1). Existe una vulnerabilidad de cross-site scripting almacenada en la Consola de Administración del producto afectado, que podría permitir a un atacante con altos privilegios inyectar código Javascript en la aplicación que luego será ejecutado por otro usuario legítimo. • https://cert-portal.siemens.com/productcert/pdf/ssa-456933.pdf • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-46098
https://notcve.org/view.php?id=CVE-2023-46098
A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). When accessing the Information Server from affected products, the products use an overly permissive CORS policy. This could allow an attacker to trick a legitimate user to trigger unwanted behavior. Se ha identificado una vulnerabilidad en SIMATIC PCS neo (todas las versiones < V4.1). Al acceder al servidor de información desde los productos afectados, los productos utilizan una política CORS demasiado permisiva. • https://cert-portal.siemens.com/productcert/pdf/ssa-456933.pdf • CWE-942: Permissive Cross-domain Policy with Untrusted Domains •
CVE-2023-46097
https://notcve.org/view.php?id=CVE-2023-46097
A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). The PUD Manager of affected products does not properly neutralize user provided inputs. This could allow an authenticated adjacent attacker to execute SQL statements in the underlying database. Se ha identificado una vulnerabilidad en SIMATIC PCS neo (todas las versiones < V4.1). El PUD Manager de los productos afectados no neutraliza adecuadamente las entradas proporcionadas por el usuario. • https://cert-portal.siemens.com/productcert/pdf/ssa-456933.pdf • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-46096
https://notcve.org/view.php?id=CVE-2023-46096
A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). The PUD Manager of affected products does not properly authenticate users in the PUD Manager web service. This could allow an unauthenticated adjacent attacker to generate a privileged token and upload additional documents. Se ha identificado una vulnerabilidad en SIMATIC PCS neo (todas las versiones < V4.1). El PUD Manager de los productos afectados no autentica adecuadamente a los usuarios en el servicio web PUD Manager. • https://cert-portal.siemens.com/productcert/pdf/ssa-456933.pdf • CWE-306: Missing Authentication for Critical Function •
CVE-2023-38558
https://notcve.org/view.php?id=CVE-2023-38558
A vulnerability has been identified in SIMATIC PCS neo (Administration Console) V4.0 (All versions), SIMATIC PCS neo (Administration Console) V4.0 Update 1 (All versions). The affected application leaks Windows admin credentials. An attacker with local access to the Administration Console could get the credentials, and impersonate the admin user, thereby gaining admin access to other Windows systems. Se ha identificado una vulnerabilidad en SIMATIC PCS neo (Consola de administración) V4.0 (todas las versiones), SIMATIC PCS neo (Consola de administración) V4.0 Update 1 (todas las versiones). La aplicación afectada pierde las credenciales de administrador de Windows. • https://cert-portal.siemens.com/productcert/pdf/ssa-646240.pdf • CWE-538: Insertion of Sensitive Information into Externally-Accessible File or Directory CWE-668: Exposure of Resource to Wrong Sphere •