CVE-2023-46281: Siemens Opcenter Quality

High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.

A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo (All versions < V4.1), SINEC NMS (All versions < V2.0 SP1), Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions < V17 Update 8), Totally Integrated Automation Portal (TIA Portal) V18 (All versions < V18 Update 3). When accessing the UMC Web-UI from affected products, UMC uses an overly permissive CORS policy. This could allow an attacker to trick a legitimate user to trigger unwanted behavior.

Affected products

  • Siemens Opcenter Quality: affected versions not specified
  • Siemens SIMATIC Pcs Neo: before 4.1 (fixed in 4.1)
  • Siemens Sinumerik Integrate Runmyhmi /automotive: affected versions not specified
  • Siemens Totally Integrated Automation Portal: from 14.0, before 15 (fixed in 15); from 15, before 16 (fixed in 16); from 16, before 17 (fixed in 17); from 17, before 18 (fixed in 18); affected versions not specified; version 18 only

Published 2023-12-12. Last modified 2026-06-17.