PT-2023-8241 · Siemens · Simatic Cn 4100
Published
2023-11-24
·
Updated
2024-01-11
·
CVE-2023-49252
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
SIMATIC CN 4100 versions prior to V2.7
Description
A vulnerability has been identified that allows IP configuration changes without authentication to the device, potentially leading to a denial of service condition. The issue is related to insufficient input validation in the software of the communication gateway SIMATIC CN 4100. This could enable a remote attacker to modify the IP configuration and cause a denial of service.
Recommendations
For versions prior to V2.7, update to version V2.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the device to prevent unauthorized IP configuration changes. Avoid using the device without proper authentication until the issue is resolved.
Fix
RCE
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Simatic Cn 4100