PT-2023-6080 · Siemens · Simatic Cp 1623+4

Published

2023-10-10

·

Updated

2023-10-16

·

CVE-2023-37195

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions SIMATIC CP 1604 versions all SIMATIC CP 1616 versions all SIMATIC CP 1623 versions all SIMATIC CP 1626 versions all SIMATIC CP 1628 versions all
Description The issue is related to insufficient control of access to memory DMA, which could allow an attacker to cause a denial of service situation on the host. This can be exploited by local attackers with administrative privileges. A physical power cycle is required to restore system functionality.
Recommendations For SIMATIC CP 1604, consider restricting access to the DMA mapping functionality until a patch is available. For SIMATIC CP 1616, avoid using administrative privileges for local attackers to minimize the risk of exploitation. For SIMATIC CP 1623, restrict the use of continuous DMA requests to prevent denial of service situations. For SIMATIC CP 1626, disable the DMA mapping feature temporarily to prevent exploitation. For SIMATIC CP 1628, limit local access to the system to prevent attackers with administrative privileges from causing a denial of service.

Fix

Improper Resource Release

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2023-06783
CVE-2023-37195

Affected Products

Simatic Cp 1604
Simatic Cp 1616
Simatic Cp 1623
Simatic Cp 1626
Simatic Cp 1628