Denial of Service Vulnerability in Siemens Automation License Manager
CVE-2016-8563

7.5HIGH

Key Information:

Vendor
Siemens
Vendor
CVE Published:
13 October 2016

Summary

A flaw in Siemens Automation License Manager prior to version 5.3 SP3 Update 1 can be exploited by remote attackers to launch a denial of service attack. By sending specially crafted packets to TCP port 4410, attackers can disrupt the ALM service, potentially halting critical automation processes and affecting system availability.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.