Input Validation Vulnerability in Siemens Automation Products
CVE-2023-46285
7.5HIGH
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 12 December 2023
Summary
An improper input validation vulnerability exists in various Siemens automation products. This flaw can be exploited by sending specially crafted messages to the service running on port 4004/tcp, potentially leading to a Denial-of-Service condition. Notably, the affected services are designed to auto-restart once a failure is detected, which may make detection of the attack more challenging.
Affected Version(s)
Opcenter Execution Foundation 0
Opcenter Quality 0
SIMATIC PCS neo 0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved