April 11, 2023, midnight |

Siemens ProductCERT Security Advisories cert-portal.siemens.com

TIA Portal contains a path traversal vulnerability that could allow the creation or overwrite of arbitrary files in the engineering system. If the user is tricked to open a malicious PC system configuration file, an attacker could exploit this vulnerability to achieve arbitrary code execution.


Siemens has released an update for TIA Portal V18 and recommends to update to the latest version. Siemens is preparing further updates and recommends specific countermeasures for products where updates are not, or not yet …

arbitrary code arbitrary code execution arbitrary files attacker code code execution configuration engineering exploit file files malicious path path traversal path traversal vulnerability portal siemens ssa system tia tia portal update vulnerability

More from cert-portal.siemens.com / Siemens ProductCERT Security Advisories

Expert Global Security Solutions Specialist

@ CHS Inc. | Inver Grove Heights, MN, US, 55077-1721

Security Operations Senior Associate - Perimeter Response

@ JPMorgan Chase & Co. | Houston, TX, United States

Cybersecurity Engineer IV

@ ManTech | 203O - CustomerSite,Washington,DC

Senior Site Reliability Engineer - Security

@ Klaviyo | Boston, MA

Information Security Specialist (Cloud Security)

@ Vertiv | Philippines

Business Value Consultant

@ Sumo Logic | United States