CVE-2023-32737 is a type confusion vulnerability in SIMATIC STEP 7 Safety V18 (all versions prior to V18 Update 2) that stems from improper restriction of the .NET BinaryFormatter during deserialization of user-controlled input. This flaw could allow an attacker to execute arbitrary code within the affected application. With a CVSS score of 6.3 (Medium), exploitation requires high privileges and user interaction, but can lead to high impacts on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Siemens | SIMATIC STEP 7 Safety V18 | >= 0, < V18 Update 2CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.