PT-2024-8119 · Siemens+1 · Simatic Ipc Diagbase+5

Published

2024-07-09

·

Updated

2024-07-09

·

CVE-2023-52891

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions: SIMATIC Energy Manager Basic versions prior to V7.5 SIMATIC Energy Manager PRO versions prior to V7.5 SIMATIC IPC DiagBase (affected versions not specified) SIMATIC IPC DiagMonitor (affected versions not specified) SIMIT V10 (affected versions not specified) SIMIT V11 versions prior to V11.1 Unified Automation .NET based OPC UA Server SDK versions prior to 3.2.2
Description: A vulnerability has been identified that may lead to high load situations and memory exhaustion, potentially blocking the server. The issue is related to improper management of sequential memory allocation. Exploitation of this vulnerability may allow an attacker to cause a denial of service.
Recommendations: For SIMATIC Energy Manager Basic versions prior to V7.5, update to version V7.5 or later. For SIMATIC Energy Manager PRO versions prior to V7.5, update to version V7.5 or later. For SIMIT V11 versions prior to V11.1, update to version V11.1 or later. For Unified Automation .NET based OPC UA Server SDK versions prior to 3.2.2, update to version 3.2.2 or later. At the moment, there is no information about a newer version that contains a fix for SIMATIC IPC DiagBase, SIMATIC IPC DiagMonitor, and SIMIT V10.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-09651
CVE-2023-52891

Affected Products

Simatic Energy Manager Basic
Simatic Energy Manager Pro
Simatic Ipc Diagbase
Simatic Ipc Diagmonitor
Simit
Unified Automation .Net Based Opc Ua Server Sdk