PT-2023-7783 · Siemens · Simatic Cp 1543Sp-1+12

Published

2023-12-12

·

Updated

2024-06-11

·

CVE-2023-38380

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions SIMATIC CP 1242-7 V2 versions prior to V3.4.29 SIMATIC CP 1243-1 versions prior to V3.4.29 SIMATIC CP 1243-1 DNP3 versions prior to V3.4.29 SIMATIC CP 1243-1 IEC versions prior to V3.4.29 SIMATIC CP 1243-7 LTE versions prior to V3.4.29 SIMATIC CP 1243-8 IRC versions prior to V3.4.29 SIMATIC CP 1542SP-1 versions prior to V2.3 SIMATIC CP 1542SP-1 IRC versions prior to V2.3 SIMATIC CP 1543-1 versions prior to V3.0.37 SIMATIC CP 1543SP-1 versions prior to V2.3 SINAMICS S210 versions 6.1 through 6.1 before HF2 SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL versions prior to V2.3 SIPLUS ET 200SP CP 1543SP-1 ISEC versions prior to V2.3 SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL versions prior to V2.3 SIPLUS NET CP 1543-1 versions prior to V3.0.37
Description The web server implementation of the affected products does not correctly release allocated memory after it has been used. An attacker with network access could use this issue to cause a denial-of-service condition in the web server of the affected product.
Recommendations For SIMATIC CP 1242-7 V2 versions prior to V3.4.29, update to version V3.4.29 or later. For SIMATIC CP 1243-1 versions prior to V3.4.29, update to version V3.4.29 or later. For SIMATIC CP 1243-1 DNP3 versions, apply the recommended fix from the manufacturer. For SIMATIC CP 1243-1 IEC versions prior to V3.4.29, update to version V3.4.29 or later. For SIMATIC CP 1243-7 LTE versions prior to V3.4.29, update to version V3.4.29 or later. For SIMATIC CP 1243-8 IRC versions prior to V3.4.29, update to version V3.4.29 or later. For SIMATIC CP 1542SP-1 versions prior to V2.3, update to version V2.3 or later. For SIMATIC CP 1542SP-1 IRC versions prior to V2.3, update to version V2.3 or later. For SIMATIC CP 1543-1 versions prior to V3.0.37, update to version V3.0.37 or later. For SIMATIC CP 1543SP-1 versions prior to V2.3, update to version V2.3 or later. For SINAMICS S210 versions 6.1 through 6.1 before HF2, apply the HF2 update. For SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL versions prior to V2.3, update to version V2.3 or later. For SIPLUS ET 200SP CP 1543SP-1 ISEC versions prior to V2.3, update to version V2.3 or later. For SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL versions prior to V2.3, update to version V2.3 or later. For SIPLUS NET CP 1543-1 versions prior to V3.0.37, update to version V3.0.37 or later.

Fix

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-08850
CVE-2023-38380

Affected Products

Simatic Cp 1242-7 V2
Simatic Cp 1243-1
Simatic Cp 1243-1 Dnp3
Simatic Cp 1243-1 Iec
Simatic Cp 1243-7 Lte Us
Simatic Cp 1243-8 Irc
Simatic Cp 1542Sp-1 Irc
Simatic Cp 1543Sp-1
Sinamics S210
Siplus Et 200Sp Cp 1542Sp-1 Irc Tx Rail
Siplus Et 200Sp Cp 1543Sp-1 Isec
Siplus Et 200Sp Cp 1543Sp-1 Isec Tx Rail
Siplus Net Cp 1543-1