Softing edgeConnector Siemens ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability
CVE-2023-27334
7.5HIGH
What is CVE-2023-27334?
The Softing edgeConnector Siemens is impacted by a vulnerability that allows remote attackers to trigger a denial-of-service condition. This vulnerability arises from the improper handling of OPC UA ConditionRefresh requests, wherein an attacker can send a barrage of requests to exhaust system resources. This exploitation does not require authentication, making it particularly concerning for affected installations. Organizations utilizing this product are advised to monitor for unusual request patterns and apply any provided security updates to mitigate potential disruptions.
Affected Version(s)
edgeConnector Siemens 3.40
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
CVSS V3.0
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
