Denial of Service Vulnerability in SIMATIC Cloud Connect Products by Siemens
CVE-2023-29105

5.9MEDIUM

Key Information:

Summary

A vulnerability has been identified in multiple versions of SIMATIC Cloud Connect 7 CC712 and CC716, allowing a denial of service situation. The flaw occurs when the devices attempt to process a non-JSON MQTT payload. An attacker controlling the communication between the MQTT broker and the affected devices can exploit this weakness, potentially rendering the devices inoperable by disrupting their ability to handle incoming data.

Affected Version(s)

SIMATIC Cloud Connect 7 CC712 All versions >= V2.0 < V2.1

SIMATIC Cloud Connect 7 CC712 All versions < V2.1

SIMATIC Cloud Connect 7 CC716 All versions >= V2.0 < V2.1

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.