CVE-2023-48363

MEDIUM

SIMATIC WinCC and OpenPCS 7 - Denial of Service via Malformed RPC Messages

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in OpenPCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 UC05), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC Route Control V9.1 (All versions < V9.1 SP2 UC05), SIMATIC WinCC Runtime Professional V18 (All versions < V18 Update 4), SIMATIC WinCC Runtime Professional V19 (All versions < V19 Update 2), SIMATIC WinCC V7.4 (All versions), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 15), SIMATIC WinCC V8.0 (All versions < V8.0 Update 4). The implementation of the RPC (Remote Procedure call) communication protocol in the affected products do not properly handle certain unorganized RPC messages. An attacker could use this vulnerability to cause a denial of service condition in the RPC server.

References (1)

Core 1

Scores

CVSS v3 6.5
EPSS 0.0009
EPSS Percentile 26.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-476
Status published
Products (9)
siemens/openpcs_7 < 9.1
siemens/simatic_batch < 9.1
siemens/simatic_pcs_7 < 9.1
siemens/simatic_route_control < 9.1
siemens/simatic_wincc 7.4
siemens/simatic_wincc 7.5
siemens/simatic_wincc 8.0
siemens/simatic_wincc_runtime_professional 19
siemens/simatic_wincc_runtime_professional < 18
Published Feb 13, 2024
Tracked Since Feb 18, 2026