Memory Exhaustion Vulnerability in SIMATIC Energy Manager and Related Products
CVE-2023-52891
5.3MEDIUM
Key Information:
- Vendor
- Siemens
- Status
- Vendor
- CVE Published:
- 9 July 2024
Summary
A significant vulnerability affects multiple Siemens products, including the SIMATIC Energy Manager and related systems. This vulnerability allows a potential attacker to exploit weaknesses in the Unified Automation .NET based OPC UA Server SDK, leading to high load situations and possible memory exhaustion. Such an attack could disrupt server operations, resulting in denial of service for legitimate users. Users of affected products are encouraged to review their system configurations and apply necessary updates to minimize exposure to this security flaw.
Affected Version(s)
SIMATIC Energy Manager Basic 0
SIMATIC Energy Manager PRO 0
SIMATIC IPC DiagBase 0
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published