CVE-2023-46281

HIGH

Siemens Opcenter Quality < 4.1 - Permissive CORS Policy

Title source: rule
STIX 2.1

Description

A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo (All versions < V4.1), SINEC NMS (All versions < V2.0 SP1), Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions < V17 Update 8), Totally Integrated Automation Portal (TIA Portal) V18 (All versions < V18 Update 3). When accessing the UMC Web-UI from affected products, UMC uses an overly permissive CORS policy. This could allow an attacker to trick a legitimate user to trigger unwanted behavior.

Scores

CVSS v3 7.1
EPSS 0.0011
EPSS Percentile 29.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-942
Status published
Products (6)
siemens/opcenter_quality
siemens/simatic_pcs_neo < 4.1
siemens/sinumerik_integrate_runmyhmi_\/automotive
siemens/totally_integrated_automation_portal
siemens/totally_integrated_automation_portal 18 (2 CPE variants)
siemens/totally_integrated_automation_portal 14.0 - 15
Published Dec 12, 2023
Tracked Since Feb 18, 2026