Description

A vulnerability has been identified in SIMATIC STEP 7 Safety V18 (All versions < V18 Update 2). Affected applications do not properly restrict the .NET BinaryFormatter when deserializing user-controllable input. This could allow an attacker to cause a type confusion and execute arbitrary code within the affected application. This is the same issue that exists for .NET BinaryFormatter https://docs.microsoft.com/en-us/visualstudio/code-quality/ca2300.

INFO

Published Date :

2024-07-09T12:04:28.195Z

Last Modified :

2025-08-27T20:32:53.574Z

Source :

siemens
AFFECTED PRODUCTS

The following products are affected by CVE-2023-32737 vulnerability.

Vendors Products
Siemens
  • Simatic Step 7
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2023-32737.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact