Web Server Login Functionality Vulnerability in Siemens Products
CVE-2023-37482

6.9MEDIUM

What is CVE-2023-37482?

A vulnerability exists in the login mechanism of Siemens web servers, where response times for login attempts are not normalized. This flaw enables an unauthenticated remote attacker to exploit timing variations to differentiate between valid and invalid usernames. As a result, attackers could potentially gain access by targeting user accounts based on the behavior of the login response, raising serious security concerns for devices relying on this functionality.

Affected Version(s)

SIMATIC Drive Controller CPU 1504D TF V3.1.0

SIMATIC Drive Controller CPU 1507D TF V3.1.0

SIMATIC ET 200SP CPU 1510SP F-1 PN V3.1.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.