The vendor explicitly identifies these products as affected by this CVE.
- SIMATIC PCS neo
- Summary
- The PUD Manager of affected products does not properly authenticate users in the PUD Manager web service. This could allow an unauthenticated adjacent attacker to generate a privileged token and upload additional documents.
- Remediation
- Update to V4.1 or later version
