Denial of Service Vulnerability in SIMATIC and SIPLUS Products by Siemens
CVE-2023-50763

4.9MEDIUM

Key Information:

Summary

A vulnerability exists in the web server components of certain SIMATIC and SIPLUS products. If configured to process PKCS12 containers, it can result in an infinite loop when handling incomplete certificate chains. This flaw can be exploited by an authenticated remote attacker to import deliberately crafted PKCS12 containers, potentially causing a denial of service. Users are advised to assess their systems and apply appropriate mitigations or updates to address this issue.

Affected Version(s)

SIMATIC CP 1542SP-1 0

SIMATIC CP 1542SP-1 IRC 0

SIMATIC CP 1543SP-1 0

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.