CVE-2024-33698
CVE-2024-33698
A vulnerability has been identified in Opcenter Quality (All versions < V2406), Opcenter RDnL (All versions < V2410), SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 2), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1), SINEC NMS (All versions), SINEMA Remote Connect Client (All versions < V3.2 SP3), Totally Integrated Automation Portal (TIA Portal) V16 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions < V17 Update 8), Totally Integrated Automation Portal (TIA Portal) V18 (All versions < V18 Update 5), Totally Integrated Automation Portal (TIA Portal) V19 (All versions < V19 Update 3). Affected products contain a heap-based buffer overflow vulnerability in the integrated UMC component. This could allow an unauthenticated remote attacker to execute arbitrary code.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Produtos afetados
Siemens · Opcenter QualitySiemens · Opcenter RDnLSiemens · SIMATIC PCS neo V4.0Siemens · SIMATIC PCS neo V4.1Siemens · SIMATIC PCS neo V5.0Siemens · SINEC NMSSiemens · SINEMA Remote Connect ClientSiemens · Totally Integrated Automation Portal (TIA Portal) V16Siemens · Totally Integrated Automation Portal (TIA Portal) V17Siemens · Totally Integrated Automation Portal (TIA Portal) V18Siemens · Totally Integrated Automation Portal (TIA Portal) V19Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →