Denial-of-Service Vulnerability in SIMATIC Products by Siemens
CVE-2023-38380
7.5HIGH
Key Information:
- Vendor
- Siemens
- Status
- Vendor
- CVE Published:
- 12 December 2023
Summary
A vulnerability exists in the webserver implementation of various SIMATIC products from Siemens, where allocated memory is not properly released after use. This flaw can be exploited by an attacker with network access, potentially leading to a denial-of-service condition in the webserver, which may disrupt the normal functioning of affected devices.
Affected Version(s)
SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) 0
SIMATIC CP 1243-1 (incl. SIPLUS variants) 0
SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) 0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved