CVE-2023-29106 MEDIUM

CVE-2023-29106

Vendor Siemens
Product SIMATIC Cloud Connect 7 CC712
Weakness CWE-200 · Info exposure
Published May 9, 2023
Last update January 28, 2025

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C

What the vulnerability does

01Description

A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2.0 < V2.1). The export endpoint is accessible via REST API without authentication. This could allow an unauthenticated remote attacker to download the files available via the endpoint.

Key dates

02Disclosure timeline

May 9, 2023 CVE published
January 28, 2025 Record updated