NA

CVE-2023-46098

Published: 14/11/2023 Updated: 20/11/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). When accessing the Information Server from affected products, the products use an overly permissive CORS policy. This could allow an malicious user to trick a legitimate user to trigger unwanted behavior.

Vulnerable Product Search on Vulmon Subscribe to Product

siemens simatic pcs neo