ID

VAR-202502-0123


CVE

CVE-2023-37482


TITLE

Siemens Multiple SIMATIC Products Web Server User Enumeration Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2025-03035

DESCRIPTION

The login functionality of the web server in affected devices does not normalize the response times of login attempts. An unauthenticated remote attacker could exploit this side-channel information to distinguish between valid and invalid usernames. SIMATIC Drive Controllers are designed for the automation of production machines and combine the functionality of the SIMATIC S7-1500 CPU and SINAMICS S120 drive control. The SIMATIC ET 200SP Open Controller is a PC-based version of the SIMATIC S7-1500 controller, including optional visualization and central I/O combinations in one compact device. The SIMATIC S7-1200 CPU products are designed for discrete and continuous control in industrial environments such as global manufacturing, food and beverage, and chemical industries. The SIMATIC S7-1200 CPU products are designed for discrete and continuous control in industrial environments such as global manufacturing, food and beverage, and chemical industries. The SIMATIC S7-1500 CPU products are designed for discrete and continuous control in industrial environments such as global manufacturing, food and beverage, and chemical industries. The SIMATIC S7-1500 Software Controller is the SIMATIC software controller for PC-based automation solutions. SIMATIC S7-PLCSIM Advanced simulates S7-1200, S7-1500 and some other PLC derivatives. Includes full network access to simulate PLCs, even in virtualized environments

Trust: 1.44

sources: NVD: CVE-2023-37482 // CNVD: CNVD-2025-03035

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-03035

AFFECTED PRODUCTS

vendor:siemensmodel:simatic drive controller familyscope:gteversion:v3.1.0,<v3.1.2

Trust: 0.6

vendor:siemensmodel:simatic et 200sp open controller cpu 1515sp pc2scope:gteversion:v30.1.0

Trust: 0.6

vendor:siemensmodel:simatic s7-1200 cpu familyscope:eqversion:v4<4.7

Trust: 0.6

vendor:siemensmodel:simatic s7-1500 cpu familyscope:gteversion:v3.1.0,<v3.1.2

Trust: 0.6

vendor:siemensmodel:simatic s7-1500 software controllerscope:gteversion:v30.1.0

Trust: 0.6

vendor:siemensmodel:simatic s7-plcsim advancedscope:gteversion:v6.0,<v7.0

Trust: 0.6

sources: CNVD: CNVD-2025-03035

CVSS

SEVERITY

CVSSV2

CVSSV3

productcert@siemens.com: CVE-2023-37482
value: MEDIUM

Trust: 1.0

CNVD: CNVD-2025-03035
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2025-03035
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

productcert@siemens.com: CVE-2023-37482
baseSeverity: MEDIUM
baseScore: 5.3
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 1.4
version: 3.1

Trust: 1.0

sources: CNVD: CNVD-2025-03035 // NVD: CVE-2023-37482

PROBLEMTYPE DATA

problemtype:CWE-203

Trust: 1.0

sources: NVD: CVE-2023-37482

EXTERNAL IDS

db:NVDid:CVE-2023-37482

Trust: 1.6

db:SIEMENSid:SSA-195895

Trust: 1.6

db:CNVDid:CNVD-2025-03035

Trust: 0.6

sources: CNVD: CNVD-2025-03035 // NVD: CVE-2023-37482

REFERENCES

url:https://cert-portal.siemens.com/productcert/html/ssa-195895.html

Trust: 1.6

sources: CNVD: CNVD-2025-03035 // NVD: CVE-2023-37482

SOURCES

db:CNVDid:CNVD-2025-03035
db:NVDid:CVE-2023-37482

LAST UPDATE DATE

2025-02-20T22:50:51.787000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-03035date:2025-02-18T00:00:00
db:NVDid:CVE-2023-37482date:2025-02-11T11:15:11.427

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-03035date:2025-02-18T00:00:00
db:NVDid:CVE-2023-37482date:2025-02-11T11:15:11.427