PT-2023-7783 · Siemens · Simatic Cp 1543Sp-1+12
Published
2023-12-12
·
Updated
2024-06-11
·
CVE-2023-38380
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
SIMATIC CP 1242-7 V2 versions prior to V3.4.29
SIMATIC CP 1243-1 versions prior to V3.4.29
SIMATIC CP 1243-1 DNP3 versions prior to V3.4.29
SIMATIC CP 1243-1 IEC versions prior to V3.4.29
SIMATIC CP 1243-7 LTE versions prior to V3.4.29
SIMATIC CP 1243-8 IRC versions prior to V3.4.29
SIMATIC CP 1542SP-1 versions prior to V2.3
SIMATIC CP 1542SP-1 IRC versions prior to V2.3
SIMATIC CP 1543-1 versions prior to V3.0.37
SIMATIC CP 1543SP-1 versions prior to V2.3
SINAMICS S210 versions 6.1 through 6.1 before HF2
SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL versions prior to V2.3
SIPLUS ET 200SP CP 1543SP-1 ISEC versions prior to V2.3
SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL versions prior to V2.3
SIPLUS NET CP 1543-1 versions prior to V3.0.37
Description
The web server implementation of the affected products does not correctly release allocated memory after it has been used. An attacker with network access could use this issue to cause a denial-of-service condition in the web server of the affected product.
Recommendations
For SIMATIC CP 1242-7 V2 versions prior to V3.4.29, update to version V3.4.29 or later.
For SIMATIC CP 1243-1 versions prior to V3.4.29, update to version V3.4.29 or later.
For SIMATIC CP 1243-1 DNP3 versions, apply the recommended fix from the manufacturer.
For SIMATIC CP 1243-1 IEC versions prior to V3.4.29, update to version V3.4.29 or later.
For SIMATIC CP 1243-7 LTE versions prior to V3.4.29, update to version V3.4.29 or later.
For SIMATIC CP 1243-8 IRC versions prior to V3.4.29, update to version V3.4.29 or later.
For SIMATIC CP 1542SP-1 versions prior to V2.3, update to version V2.3 or later.
For SIMATIC CP 1542SP-1 IRC versions prior to V2.3, update to version V2.3 or later.
For SIMATIC CP 1543-1 versions prior to V3.0.37, update to version V3.0.37 or later.
For SIMATIC CP 1543SP-1 versions prior to V2.3, update to version V2.3 or later.
For SINAMICS S210 versions 6.1 through 6.1 before HF2, apply the HF2 update.
For SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL versions prior to V2.3, update to version V2.3 or later.
For SIPLUS ET 200SP CP 1543SP-1 ISEC versions prior to V2.3, update to version V2.3 or later.
For SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL versions prior to V2.3, update to version V2.3 or later.
For SIPLUS NET CP 1543-1 versions prior to V3.0.37, update to version V3.0.37 or later.
Fix
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simatic Cp 1242-7 V2
Simatic Cp 1243-1
Simatic Cp 1243-1 Dnp3
Simatic Cp 1243-1 Iec
Simatic Cp 1243-7 Lte Us
Simatic Cp 1243-8 Irc
Simatic Cp 1542Sp-1 Irc
Simatic Cp 1543Sp-1
Sinamics S210
Siplus Et 200Sp Cp 1542Sp-1 Irc Tx Rail
Siplus Et 200Sp Cp 1543Sp-1 Isec
Siplus Et 200Sp Cp 1543Sp-1 Isec Tx Rail
Siplus Net Cp 1543-1