CVE-2023-38533

A vulnerability has been identified in TIA Administrator (All versions < V3 SP2). The affected component creates temporary download files in a directory with insecure permissions. This could allow any authenticated attacker on Windows to disrupt the update process.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:siemens:tia_administrator:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:tia_administrator:3.0:-:*:*:*:*:*:*
cpe:2.3:a:siemens:tia_administrator:3.0:sp1:*:*:*:*:*:*

History

21 Aug 2025, 16:14

Type Values Removed Values Added
References () https://cert-portal.siemens.com/productcert/html/ssa-319319.html - () https://cert-portal.siemens.com/productcert/html/ssa-319319.html - Vendor Advisory
First Time Siemens
Siemens tia Administrator
CPE cpe:2.3:a:siemens:tia_administrator:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:tia_administrator:3.0:sp1:*:*:*:*:*:*
cpe:2.3:a:siemens:tia_administrator:3.0:-:*:*:*:*:*:*

21 Nov 2024, 08:13

Type Values Removed Values Added
References () https://cert-portal.siemens.com/productcert/html/ssa-319319.html - () https://cert-portal.siemens.com/productcert/html/ssa-319319.html -
Summary
  • (es) Se ha identificado una vulnerabilidad en TIA Administrator (Todas las versiones &lt; V3 SP2). El componente afectado crea archivos de descarga temporales en un directorio con permisos inseguros. Esto podría permitir que cualquier atacante autenticado en Windows interrumpa el proceso de actualización.

11 Jun 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-11 12:15

Updated : 2025-08-21 16:14


NVD link : CVE-2023-38533

Mitre link : CVE-2023-38533

CVE.ORG link : CVE-2023-38533


JSON object : View

Products Affected

siemens

  • tia_administrator
CWE
CWE-379

Creation of Temporary File in Directory with Insecure Permissions