Junglewise Threat Intelligence

CVE-2023-45795: Pilz PASvisu XSS in Builder Component

CVE-2023-45795 · Severity: high · CVSS 7.8 · Published 2026-06-22

Executive brief

Pilz PASvisu is a visualization software used in industrial automation to design and operate machine interfaces. A security flaw in the Builder component allows an attacker to gain full control over the system by tricking a user into opening a malicious project file. This could lead to unauthorized access to industrial control processes, data theft, or complete system takeover.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the Builder Component of Pilz PASvisu before version 1.14.1 and PMI v8xx firmware up to 2.0.33992. The vulnerability is triggered when a user interacts with a malicious project file (User Interaction required). Because the Builder component may run with elevated privileges, successful exploitation allows an unauthenticated local attacker to inject JavaScript that executes arbitrary code in the context of the application. This can result in a complete compromise of the workstation or the connected automation environment. Users are advised to upgrade to PASvisu 1.14.1 or later and only open project files from trusted sources.

Affected products

  • Pilz PASvisu < 1.14.1
  • Pilz PMI v8xx Firmware <= 2.0.33992

Timeline

  • 2024-01-30: advisory: Initial advisory published by CERT@VDE
  • 2026-06-22: disclosed: CVE published to NVD dataset

References

Related threats