CVE-2023-38533

A vulnerability has been identified in TIA Administrator (All versions < V3 SP2). The affected component creates temporary download files in a directory with insecure permissions. This could allow any authenticated attacker on Windows to disrupt the update process.
Configurations

No configuration.

History

21 Nov 2024, 08:13

Type Values Removed Values Added
References () https://cert-portal.siemens.com/productcert/html/ssa-319319.html - () https://cert-portal.siemens.com/productcert/html/ssa-319319.html -
Summary
  • (es) Se ha identificado una vulnerabilidad en TIA Administrator (Todas las versiones &lt; V3 SP2). El componente afectado crea archivos de descarga temporales en un directorio con permisos inseguros. Esto podría permitir que cualquier atacante autenticado en Windows interrumpa el proceso de actualización.

11 Jun 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-11 12:15

Updated : 2024-11-21 08:13


NVD link : CVE-2023-38533

Mitre link : CVE-2023-38533

CVE.ORG link : CVE-2023-38533


JSON object : View

Products Affected

No product.

CWE
CWE-379

Creation of Temporary File in Directory with Insecure Permissions