Successful exploitation of this vulnerability, which Siemens self-reported, could allow a local attacker to decrypt intercepted local traffic between the browser and the application. A local attacker could perform a machine-in-the-middle attack to modify data in transit.
In the vulnerability, the Adaptec maxView application uses a non-unique TLS certificate across installations to protect communication from the local browser to the local application on affected Siemens devices. A local attacker could use this key to decrypt intercepted local traffic between the browser and the application and could perform a machine-in-the-middle attack to modify data in transit.
CVE-2023-23588 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 6.2.
The following software from Siemens suffers from the issue:
- SIMATIC IPC1047: All versions
- SIMATIC IPC1047E: All versions with Adaptec maxView Storage Manager prior to 4.09.00.25611 on Windows
- SIMATIC IPC647D: All versions
- SIMATIC IPC647E: All versions with Adaptec maxView Storage Manager prior to 4.09.00.25611 on Windows
- SIMATIC IPC847D: All versions
- SIMATIC IPC847E: All versions with Adaptec maxView Storage Manager prior to 4.09.00.25611 on Windows
The product sees use in multiple industrial sectors, and on a global basis.
No known public exploits specifically target this vulnerability. This vulnerability is not exploitable remotely. However, an attacker could leverage this low complexity vulnerability.
Adaptec released updates for the affected products and recommends updating to the latest versions. Siemens recommends countermeasures for products where updates are not, or not yet available: Update maxView Storage Manager to 4.09.00.25611 or later version.
Siemens identified the following specific workarounds and mitigations users can apply to reduce risk: Update the default self-signed device X.509 certificate with a trusted certificate.
As a general security measure, Siemens recommends protecting network access to devices with appropriate mechanisms. To operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens’ operational guidelines for industrial security and to follow recommendations in the product manuals.
For more information, click on Siemens security advisory SSA-511182.

