Medium severity6.5NVD Advisory· Published Nov 14, 2023· Updated Jun 17, 2026
CVE-2023-46096
CVE-2023-46096
Description
A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). The PUD Manager of affected products does not properly authenticate users in the PUD Manager web service. This could allow an unauthenticated adjacent attacker to generate a privileged token and upload additional documents.
Affected products
3- Range: All versions < V4.1
<V4.1+ 1 more
- (no CPE)range: <V4.1
- cpe:2.3:a:siemens:simatic_pcs_neo:*:*:*:*:*:*:*:*range: <4.1
Patches
Vulnerability mechanics
References
1- cert-portal.siemens.com/productcert/pdf/ssa-456933.pdfnvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.