Vulnerability Details CVE-2023-46096
A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). The PUD Manager of affected products does not properly authenticate users in the PUD Manager web service. This could allow an unauthenticated adjacent attacker to generate a privileged token and upload additional documents.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 20.8%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2023-46096
-
cpe:2.3:a:siemens:simatic_pcs_neo:-
-
cpe:2.3:a:siemens:simatic_pcs_neo:3.0
-
cpe:2.3:a:siemens:simatic_pcs_neo:3.1
-
cpe:2.3:a:siemens:simatic_pcs_neo:4.0