VulnerabilityModified
CVE-2023-44321
Affected devices do not properly validate the length of inputs when performing certain configuration changes in the web interface allowing an authenticated attacker to cause a denial of service condition.
MEDIUM 5.1EPSS 1.00%
Does this matter?
Lower severity and a low EPSS score (1.00%). Track it; it rarely justifies an emergency change on its own.
Description
Affected devices do not properly validate the length of inputs when performing certain configuration changes in the web interface allowing an authenticated attacker to cause a denial of service condition. The device needs to be restarted for the web interface to become available again.
- CVSS 4.0
- 5.1 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 1.00% probability · 61th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400
- Affected
- siemens/6gk5205-3bb00-2ab2 firmware · siemens/6gk5205-3bb00-2tb2 firmware · siemens/6gk5205-3bd00-2tb2 firmware · siemens/6gk5205-3bd00-2ab2 firmware · siemens/6gk5205-3bf00-2tb2 firmware · siemens/6gk5205-3bf00-2ab2 firmware · siemens/6gk5208-0ba00-2tb2 firmware · siemens/6gk5208-0ba00-2ab2 firmware · siemens/6gk5213-3bd00-2tb2 firmware · siemens/6gk5213-3bd00-2ab2 firmware · siemens/6gk5213-3bb00-2tb2 firmware · siemens/6gk5213-3bb00-2ab2 firmware · siemens/6gk5213-3bf00-2tb2 firmware · siemens/6gk5213-3bf00-2ab2 firmware · siemens/6gk5216-0ba00-2tb2 firmware · siemens/6gk5216-0ba00-2ab2 firmware · siemens/6gk5206-2bd00-2ac2 firmware · siemens/6gk5206-2bb00-2ac2 firmware · siemens/6gk5206-2rs00-2ac2 firmware · siemens/6gk5206-2rs00-5ac2 firmware · +40 more
- Source
- productcert@siemens.com
References
- https://cert-portal.siemens.com/productcert/html/ssa-087301.html
- https://cert-portal.siemens.com/productcert/html/ssa-180704.html
- https://cert-portal.siemens.com/productcert/html/ssa-353002.html
- https://cert-portal.siemens.com/productcert/html/ssa-602936.html
- https://cert-portal.siemens.com/productcert/html/ssa-699386.html
- https://cert-portal.siemens.com/productcert/pdf/ssa-180704.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-699386.pdfVendor Advisory
- https://cert-portal.siemens.com/productcert/html/ssa-180704.html
- https://cert-portal.siemens.com/productcert/html/ssa-353002.html
- https://cert-portal.siemens.com/productcert/html/ssa-602936.html
- https://cert-portal.siemens.com/productcert/html/ssa-699386.html
- https://cert-portal.siemens.com/productcert/pdf/ssa-180704.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-699386.pdfVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.