CVE-2023-52891: Siemens SIMATIC Energy Manager Basic

Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.

A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.5), SIMATIC Energy Manager PRO (All versions < V7.5), SIMATIC IPC DiagBase (All versions), SIMATIC IPC DiagMonitor (All versions), SIMIT V10 (All versions), SIMIT V11 (All versions < V11.1). Unified Automation .NET based OPC UA Server SDK before 3.2.2 used in Siemens products are affected by a similar vulnerability as documented in CVE-2023-27321 for the OPC Foundation UA .NET Standard implementation. A successful attack may lead to high load situation and memory exhaustion, and may block the server.

Affected products

  • Siemens SIMATIC Energy Manager Basic: before V7.5 (fixed in V7.5)
  • Siemens SIMATIC Energy Manager Pro: before V7.5 (fixed in V7.5)
  • Siemens SIMATIC Ipc Diagbase: any version
  • Siemens SIMATIC Ipc Diagmonitor: any version
  • Siemens Simit v10: any version
  • Siemens Simit v11: before V11.1 (fixed in V11.1)

Published 2024-07-09. Last modified 2026-06-17.