Denial of Service Vulnerability in Siemens SIMATIC MV540 and MV550 Series
CVE-2023-35921
7.5HIGH
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 11 July 2023
Summary
A vulnerability has been discovered in the Siemens SIMATIC MV540 and MV550 series devices, specifically affecting all versions prior to V3.3.4. These devices fail to properly handle specially crafted Ethernet frames, which allows an unauthenticated remote attacker to trigger a denial of service condition. As a result, the impacted devices may require manual restarting to restore normal functionality. Users of these products are advised to upgrade to the latest version to mitigate this risk.
Affected Version(s)
SIMATIC MV540 H All versions < V3.3.4
SIMATIC MV540 S All versions < V3.3.4
SIMATIC MV550 H All versions < V3.3.4
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved