CVE-2023-23588
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability has been identified in SIMATIC IPC1047 (All versions), SIMATIC IPC1047E (All versions with maxView Storage Manager < 4.09.00.25611 on Windows), SIMATIC IPC647D (All versions), SIMATIC IPC647E (All versions with maxView Storage Manager < 4.09.00.25611 on Windows), SIMATIC IPC847D (All versions), SIMATIC IPC847E (All versions with maxView Storage Manager < 4.09.00.25611 on Windows). The Adaptec Maxview application on affected devices is using a non-unique TLS certificate across installations to protect the communication from the local browser to the local application.
A local attacker may use this key to decrypt intercepted local traffic between the browser and the application and could perform a man-in-the-middle attack in order to modify data in transit.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-01-13 CVE Reserved
- 2023-04-11 CVE Published
- 2023-04-20 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-295: Improper Certificate Validation
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-511182.pdf | 2024-01-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Siemens Search vendor "Siemens" | Simatic Ipc647d Firmware Search vendor "Siemens" for product "Simatic Ipc647d Firmware" | * | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc647d Search vendor "Siemens" for product "Simatic Ipc647d" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc847d Firmware Search vendor "Siemens" for product "Simatic Ipc847d Firmware" | * | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc847d Search vendor "Siemens" for product "Simatic Ipc847d" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Ipc1047 Firmware Search vendor "Siemens" for product "Simatic Ipc1047 Firmware" | * | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc1047 Search vendor "Siemens" for product "Simatic Ipc1047" | - | - |
Safe
|
Microchip Search vendor "Microchip" | Maxview Storage Manager Search vendor "Microchip" for product "Maxview Storage Manager" | < 4.09.00.25611 Search vendor "Microchip" for product "Maxview Storage Manager" and version " < 4.09.00.25611" | windows |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc1047e Search vendor "Siemens" for product "Simatic Ipc1047e" | - | - |
Safe
|
Microchip Search vendor "Microchip" | Maxview Storage Manager Search vendor "Microchip" for product "Maxview Storage Manager" | < 4.09.00.25611 Search vendor "Microchip" for product "Maxview Storage Manager" and version " < 4.09.00.25611" | windows |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc647e Search vendor "Siemens" for product "Simatic Ipc647e" | - | - |
Safe
|
Microchip Search vendor "Microchip" | Maxview Storage Manager Search vendor "Microchip" for product "Maxview Storage Manager" | < 4.09.00.25611 Search vendor "Microchip" for product "Maxview Storage Manager" and version " < 4.09.00.25611" | windows |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Ipc847e Search vendor "Siemens" for product "Simatic Ipc847e" | - | - |
Safe
|