Web Server Login Functionality Vulnerability in Siemens Products
CVE-2023-37482
Key Information:
- Vendor
Siemens
- Status
- Vendor
- CVE Published:
- 11 February 2025
What is CVE-2023-37482?
A vulnerability exists in the login mechanism of Siemens web servers, where response times for login attempts are not normalized. This flaw enables an unauthenticated remote attacker to exploit timing variations to differentiate between valid and invalid usernames. As a result, attackers could potentially gain access by targeting user accounts based on the behavior of the login response, raising serious security concerns for devices relying on this functionality.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SIMATIC Drive Controller CPU 1504D TF V3.1.0
SIMATIC Drive Controller CPU 1507D TF V3.1.0
SIMATIC ET 200SP CPU 1510SP F-1 PN V3.1.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved