Denial of Service Vulnerability in Siemens SIMATIC Products
CVE-2023-30755
Key Information:
- Vendor
Siemens
- Status
- Vendor
- CVE Published:
- 10 September 2024
What is CVE-2023-30755?
A significant vulnerability exists within a range of Siemens SIMATIC devices that impacts how the integrated web server processes shutdown and reboot requests. This improper handling can result in certain resources not being correctly cleaned up. An attacker with elevated privileges could exploit this vulnerability remotely, potentially leading to a denial of service condition that disrupts the normal operation of the affected systems. Organizations using these products should assess their security posture in relation to this vulnerability and implement appropriate measures to mitigate any risks associated.
Affected Version(s)
SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) 0
SIMATIC CP 1243-1 (incl. SIPLUS variants) 0
SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) 0