Denial of Service Vulnerability in SIMATIC and SIPLUS Products by Siemens
CVE-2023-50763
4.9MEDIUM
Key Information:
- Vendor
Siemens
- Status
- Vendor
- CVE Published:
- 11 June 2024
What is CVE-2023-50763?
A vulnerability exists in the web server components of certain SIMATIC and SIPLUS products. If configured to process PKCS12 containers, it can result in an infinite loop when handling incomplete certificate chains. This flaw can be exploited by an authenticated remote attacker to import deliberately crafted PKCS12 containers, potentially causing a denial of service. Users are advised to assess their systems and apply appropriate mitigations or updates to address this issue.
Affected Version(s)
SIMATIC CP 1542SP-1 0
SIMATIC CP 1542SP-1 IRC 0
SIMATIC CP 1543SP-1 0