CVE-2023-46099

MEDIUM

SIMATIC PCS neo < 4.1 - Stored Cross-Site Scripting in Administration Console

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). There is a stored cross-site scripting vulnerability in the Administration Console of the affected product, that could allow an attacker with high privileges to inject Javascript code into the application that is later executed by another legitimate user.

References (1)

Core 1

Scores

CVSS v3 5.4
EPSS 0.0010
EPSS Percentile 27.4%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
siemens/simatic_pcs_neo < 4.1
Published Nov 14, 2023
Tracked Since Feb 18, 2026