High severity8.0NVD Advisory· Published Nov 14, 2023· Updated Jun 17, 2026
CVE-2023-46098
CVE-2023-46098
Description
A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). When accessing the Information Server from affected products, the products use an overly permissive CORS policy. This could allow an attacker to trick a legitimate user to trigger unwanted behavior.
Affected products
3- Range: All versions < V4.1
cpe:2.3:a:siemens:simatic_pcs_neo:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:siemens:simatic_pcs_neo:*:*:*:*:*:*:*:*range: <4.1
- (no CPE)range: <V4.1
Patches
Vulnerability mechanics
References
1- cert-portal.siemens.com/productcert/pdf/ssa-456933.pdfnvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.