CVE-2023-46285: Siemens Opcenter Quality

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo (All versions < V4.1), SINEC NMS (All versions < V2.0 SP1), Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions < V17 Update 8), Totally Integrated Automation Portal (TIA Portal) V18 (All versions < V18 Update 3). The affected application contains an improper input validation vulnerability that could allow an attacker to bring the service into a Denial-of-Service state by sending a specifically crafted message to 4004/tcp. The corresponding service is auto-restarted after the crash is detected by a watchdog.

Affected products

  • Siemens Opcenter Quality: affected versions not specified
  • Siemens SIMATIC Pcs Neo: before 4.1 (fixed in 4.1)
  • Siemens Sinumerik Integrate Runmyhmi /automotive: affected versions not specified
  • Siemens Totally Integrated Automation Portal: from 14.0, before 15 (fixed in 15); from 15, before 16 (fixed in 16); from 16, before 17 (fixed in 17); from 17, before 18 (fixed in 18); affected versions not specified; version 18 only

Published 2023-12-12. Last modified 2026-06-17.