Input Validation Vulnerability in Siemens Automation Products
CVE-2023-46285

7.5HIGH

Key Information:

Vendor
Siemens
Vendor
CVE Published:
12 December 2023

Summary

An improper input validation vulnerability exists in various Siemens automation products. This flaw can be exploited by sending specially crafted messages to the service running on port 4004/tcp, potentially leading to a Denial-of-Service condition. Notably, the affected services are designed to auto-restart once a failure is detected, which may make detection of the attack more challenging.

Affected Version(s)

Opcenter Execution Foundation 0

Opcenter Quality 0

SIMATIC PCS neo 0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.