Denial of Service Vulnerability in SIMATIC Cloud Connect Products by Siemens
CVE-2023-29105
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 9 May 2023
What is CVE-2023-29105?
A vulnerability has been identified in multiple versions of SIMATIC Cloud Connect 7 CC712 and CC716, allowing a denial of service situation. The flaw occurs when the devices attempt to process a non-JSON MQTT payload. An attacker controlling the communication between the MQTT broker and the affected devices can exploit this weakness, potentially rendering the devices inoperable by disrupting their ability to handle incoming data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SIMATIC Cloud Connect 7 CC712 All versions >= V2.0 < V2.1
SIMATIC Cloud Connect 7 CC712 All versions < V2.1
SIMATIC Cloud Connect 7 CC716 All versions >= V2.0 < V2.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved