CVE-2023-44374

high

Description

Affected devices allow to change the password, but insufficiently check which password is to be changed. With this an authenticated attacker could, under certain conditions, be able to change the password of another, potential admin user allowing her to escalate her privileges.

References

https://cert-portal.siemens.com/productcert/pdf/ssa-699386.pdf

https://cert-portal.siemens.com/productcert/pdf/ssa-180704.pdf

https://cert-portal.siemens.com/productcert/html/ssa-699386.html

https://cert-portal.siemens.com/productcert/html/ssa-180704.html

Details

Source: Mitre, NVD

Published: 2023-11-14

Updated: 2024-03-12

Risk Information

CVSS v2

Base Score: 9

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High