// For flags

CVE-2023-23588

 

Severity Score

6.3
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A vulnerability has been identified in SIMATIC IPC1047 (All versions), SIMATIC IPC1047E (All versions with maxView Storage Manager < 4.09.00.25611 on Windows), SIMATIC IPC647D (All versions), SIMATIC IPC647E (All versions with maxView Storage Manager < 4.09.00.25611 on Windows), SIMATIC IPC847D (All versions), SIMATIC IPC847E (All versions with maxView Storage Manager < 4.09.00.25611 on Windows). The Adaptec Maxview application on affected devices is using a non-unique TLS certificate across installations to protect the communication from the local browser to the local application.
A local attacker may use this key to decrypt intercepted local traffic between the browser and the application and could perform a man-in-the-middle attack in order to modify data in transit.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2023-01-13 CVE Reserved
  • 2023-04-11 CVE Published
  • 2023-04-20 EPSS Updated
  • 2024-08-02 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
  • CWE-295: Improper Certificate Validation
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Siemens
Search vendor "Siemens"
Simatic Ipc647d Firmware
Search vendor "Siemens" for product "Simatic Ipc647d Firmware"
*-
Affected
in Siemens
Search vendor "Siemens"
Simatic Ipc647d
Search vendor "Siemens" for product "Simatic Ipc647d"
--
Safe
Siemens
Search vendor "Siemens"
Simatic Ipc847d Firmware
Search vendor "Siemens" for product "Simatic Ipc847d Firmware"
*-
Affected
in Siemens
Search vendor "Siemens"
Simatic Ipc847d
Search vendor "Siemens" for product "Simatic Ipc847d"
--
Safe
Siemens
Search vendor "Siemens"
Simatic Ipc1047 Firmware
Search vendor "Siemens" for product "Simatic Ipc1047 Firmware"
*-
Affected
in Siemens
Search vendor "Siemens"
Simatic Ipc1047
Search vendor "Siemens" for product "Simatic Ipc1047"
--
Safe
Microchip
Search vendor "Microchip"
Maxview Storage Manager
Search vendor "Microchip" for product "Maxview Storage Manager"
< 4.09.00.25611
Search vendor "Microchip" for product "Maxview Storage Manager" and version " < 4.09.00.25611"
windows
Affected
in Siemens
Search vendor "Siemens"
Simatic Ipc1047e
Search vendor "Siemens" for product "Simatic Ipc1047e"
--
Safe
Microchip
Search vendor "Microchip"
Maxview Storage Manager
Search vendor "Microchip" for product "Maxview Storage Manager"
< 4.09.00.25611
Search vendor "Microchip" for product "Maxview Storage Manager" and version " < 4.09.00.25611"
windows
Affected
in Siemens
Search vendor "Siemens"
Simatic Ipc647e
Search vendor "Siemens" for product "Simatic Ipc647e"
--
Safe
Microchip
Search vendor "Microchip"
Maxview Storage Manager
Search vendor "Microchip" for product "Maxview Storage Manager"
< 4.09.00.25611
Search vendor "Microchip" for product "Maxview Storage Manager" and version " < 4.09.00.25611"
windows
Affected
in Siemens
Search vendor "Siemens"
Simatic Ipc847e
Search vendor "Siemens" for product "Simatic Ipc847e"
--
Safe