Denial-of-Service Vulnerability in SIMATIC Products by Siemens
CVE-2023-38380
7.5HIGH
Key Information:
- Vendor
Siemens
- Status
- Vendor
- CVE Published:
- 12 December 2023
What is CVE-2023-38380?
A vulnerability exists in the webserver implementation of various SIMATIC products from Siemens, where allocated memory is not properly released after use. This flaw can be exploited by an attacker with network access, potentially leading to a denial-of-service condition in the webserver, which may disrupt the normal functioning of affected devices.
Affected Version(s)
SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) 0
SIMATIC CP 1243-1 (incl. SIPLUS variants) 0
SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) 0