VDB

CNVD-2024-31242

CNVD-2024-31242 PUBLISHED CVSS 6.5 MEDIUM

Totally Integrated Automation Portal (TIA Portal)是一款PC软件,可提供西门子数字化自动化服务的完整范围,从数字规划、集成工程到透明操作。 Siemens Engineering Platforms目录配置文件存在反序列化漏洞,攻击者可利用该漏洞造成类型混淆,并在受影响的应用程序中执行任意代码。

Risk Scores

CVSS v3.1
6.5
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C

Affected Products

VendorProductVersions
SiemensSIRIUS Safety ES V170
SiemensSIMATIC STEP 7 Safety V160
siemenstia_portal_cloud_v3.00
SiemensSoft Starter ES V160
SiemensSIMOTION SCOUT TIA V5.4 SP30
siemenssimotion_scout_tiav5.5sp1, v5.4sp3, v5.4sp1
SiemensSIRIUS Soft Starter ES V180
siemenssimatic_wincc_unified0, 0, 0
siemenssimatic_step_70, 0, 0
SiemensSIMATIC STEP 7 Safety V170
SiemensSIMOCODE ES V180
SiemensSINAMICS Startdrive V160
SiemensSINAMICS Startdrive V170
SiemensSIMOCODE ES V170
SiemensSIMATIC STEP 7 V170
SiemensSIMATIC STEP 7 V160
SiemensSIMATIC WinCC Unified V180
SiemensSIMOTION SCOUT TIA V5.5 SP10
SiemensSIMATIC WinCC Unified V160
SiemensSIMOTION SCOUT TIA V5.4 SP10

…and 18 more

Timeline

  • Jul 9, 2024 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›