This content is restricted.
Brief
Summary:
A cybersecurity advisory issued by CISA (Cybersecurity and Infrastructure Security Agency) on January 10, 2023, regarding Siemens Polarion ALM product vulnerabilities. The advisory indicates that the vulnerabilities, CVE-2023-50236 and CVE-2024-23813, can allow unauthenticated access or privilege escalation. The affected product is Siemens Polarion ALM, all versions, and the vulnerabilities are related to incorrect default permissions and improper authentication. The advisory recommends countermeasures, workarounds, and mitigations, including restrictive permissions, Apache configuration changes, and limiting access to the doorsconnector endpoint. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets and report suspected malicious activity.
Highlights content goes here...
This content is restricted.
