Denial-of-Service Vulnerability in SIMATIC Products by Siemens
CVE-2023-38380

7.5HIGH

Summary

A vulnerability exists in the webserver implementation of various SIMATIC products from Siemens, where allocated memory is not properly released after use. This flaw can be exploited by an attacker with network access, potentially leading to a denial-of-service condition in the webserver, which may disrupt the normal functioning of affected devices.

Affected Version(s)

SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) 0

SIMATIC CP 1243-1 (incl. SIPLUS variants) 0

SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) 0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.