Medium severity6.0NVD Advisory· Published May 9, 2023· Updated Jun 17, 2026
CVE-2023-29104
CVE-2023-29104
Description
A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2.0 < V2.1). The filename in the upload feature of the web based management of the affected device is susceptible to a path traversal vulnerability. This could allow an authenticated privileged remote attacker to overwrite any file the Linux user ccuser has write access to, or to download any file the Linux user ccuser has read-only access to.
Affected products
5- cpe:2.3:o:siemens:6gk1411-1ac00_firmware:2.0:*:*:*:*:*:*:*
- cpe:2.3:o:siemens:6gk1411-5ac00_firmware:2.0:*:*:*:*:*:*:*
>=V2.0 <V2.1+ 2 more
- (no CPE)range: >=V2.0 <V2.1
- (no CPE)range: All versions >= V2.0 < V2.1
- (no CPE)range: All versions >= V2.0 < V2.1
Patches
Vulnerability mechanics
References
1- cert-portal.siemens.com/productcert/pdf/ssa-555292.pdfnvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.