Denial of Service Vulnerability in SIMATIC Cloud Connect Products by Siemens
CVE-2023-29105
5.9MEDIUM
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 9 May 2023
What is CVE-2023-29105?
A vulnerability has been identified in multiple versions of SIMATIC Cloud Connect 7 CC712 and CC716, allowing a denial of service situation. The flaw occurs when the devices attempt to process a non-JSON MQTT payload. An attacker controlling the communication between the MQTT broker and the affected devices can exploit this weakness, potentially rendering the devices inoperable by disrupting their ability to handle incoming data.
Affected Version(s)
SIMATIC Cloud Connect 7 CC712 All versions >= V2.0 < V2.1
SIMATIC Cloud Connect 7 CC712 All versions < V2.1
SIMATIC Cloud Connect 7 CC716 All versions >= V2.0 < V2.1