Denial of Service Vulnerability in SIMATIC Cloud Connect Products by Siemens
CVE-2023-29105
5.9MEDIUM
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 9 May 2023
Summary
A vulnerability has been identified in multiple versions of SIMATIC Cloud Connect 7 CC712 and CC716, allowing a denial of service situation. The flaw occurs when the devices attempt to process a non-JSON MQTT payload. An attacker controlling the communication between the MQTT broker and the affected devices can exploit this weakness, potentially rendering the devices inoperable by disrupting their ability to handle incoming data.
Affected Version(s)
SIMATIC Cloud Connect 7 CC712 All versions >= V2.0 < V2.1
SIMATIC Cloud Connect 7 CC712 All versions < V2.1
SIMATIC Cloud Connect 7 CC716 All versions >= V2.0 < V2.1
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved