Heap-based Buffer Overflow Vulnerability in SCALANCE LPE9403 by Siemens
CVE-2023-27410
2.7LOW
Summary
A heap-based buffer overflow vulnerability has been identified in the SCALANCE LPE9403 product from Siemens. This issue resides within the edgebox_web_app
binary, which is susceptible to crashing when a backup password exceeding 255 characters is provided. An authenticated user with elevated privileges could exploit this vulnerability to induce a denial of service, making it crucial for users of SCALANCE LPE9403 to assess their systems and implement necessary security measures.
Affected Version(s)
SCALANCE LPE9403 All versions < V2.1
References
CVSS V3.1
Score:
2.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved