Multiple Vulnerabilities in SIMATIC PCS neo before V4.1
Plan Patch8SSA-456933Nov 14, 2023
Attack VectorAdjacent
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary
SIMATIC PCS neo before V4.1 is affected by multiple vulnerabilities including missing authentication (CWE-306), SQL injection (CWE-89), insufficient access controls (CWE-942), and cross-site scripting (CWE-79).
What this means
What could happen
An attacker could exploit these vulnerabilities to inject malicious SQL commands, perform unauthorized actions without proper authentication, or inject scripts to compromise operator workstations and potentially alter control logic or process data.
Who's at risk
This affects operators and engineers using SIMATIC PCS neo for process automation and control across sectors including water treatment, wastewater, power generation, and chemical manufacturing. The vulnerability impacts engineering workstations and the central control server where process logic and setpoints are configured and monitored.
How it could be exploited
An attacker with network access to SIMATIC PCS neo could submit malicious SQL queries to bypass authentication or modify database records, or inject scripts through the web interface to execute arbitrary commands on the engineering workstation or interfaced control systems.
Prerequisites
- Network access to SIMATIC PCS neo service
- No valid credentials required (missing authentication)
- User interaction may be required to trigger script injection (CWE-79)
Remotely exploitableNo authentication requiredLow complexity attackAffects engineering workstations and control logicHigh CVSS score (8.0)
Exploitability
Low exploit probability (EPSS 0.2%)
Affected products (1)
ProductAffected VersionsFix Status
SIMATIC PCS neo<V4.14.1
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXUpdate SIMATIC PCS neo to version 4.1 or later
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/e89408f3-ca47-46dc-a40c-7d9e7b5b591b