CVE-2023-26293

HIGH

TIA Portal <V16.7, <V17.6, <V18.1 - Path Traversal

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in Totally Integrated Automation Portal (TIA Portal) V15 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All versions < V16 Update 7), Totally Integrated Automation Portal (TIA Portal) V17 (All versions < V17 Update 6), Totally Integrated Automation Portal (TIA Portal) V18 (All versions < V18 Update 1). Affected products contain a path traversal vulnerability that could allow the creation or overwrite of arbitrary files in the engineering system. If the user is tricked to open a malicious PC system configuration file, an attacker could exploit this vulnerability to achieve arbitrary code execution.

Scores

CVSS v3 7.3
EPSS 0.0012
EPSS Percentile 30.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22 CWE-20
Status published
Products (4)
siemens/tia_portal 15
siemens/tia_portal 16
siemens/tia_portal 17 (6 CPE variants)
siemens/tia_portal 18
Published Apr 11, 2023
Tracked Since Feb 18, 2026