Medium severity6.3NVD Advisory· Published Nov 14, 2023· Updated Jun 17, 2026
CVE-2023-46097
CVE-2023-46097
Description
A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). The PUD Manager of affected products does not properly neutralize user provided inputs. This could allow an authenticated adjacent attacker to execute SQL statements in the underlying database.
Affected products
3- Range: All versions < V4.1
cpe:2.3:a:siemens:simatic_pcs_neo:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:siemens:simatic_pcs_neo:*:*:*:*:*:*:*:*range: <4.1
- (no CPE)range: <V4.1
Patches
Vulnerability mechanics
References
1- cert-portal.siemens.com/productcert/pdf/ssa-456933.pdfnvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.