PT-2023-6080 · Siemens · Simatic Cp 1623+4

CVE-2023-37195

·

Publicado

2023-10-10

·

Atualizado

2023-10-16

CVSS v2.0

4.9

Média

VetorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions SIMATIC CP 1604 versions all SIMATIC CP 1616 versions all SIMATIC CP 1623 versions all SIMATIC CP 1626 versions all SIMATIC CP 1628 versions all
Description The issue is related to insufficient control of access to memory DMA, which could allow an attacker to cause a denial of service situation on the host. This can be exploited by local attackers with administrative privileges. A physical power cycle is required to restore system functionality.
Recommendations For SIMATIC CP 1604, consider restricting access to the DMA mapping functionality until a patch is available. For SIMATIC CP 1616, avoid using administrative privileges for local attackers to minimize the risk of exploitation. For SIMATIC CP 1623, restrict the use of continuous DMA requests to prevent denial of service situations. For SIMATIC CP 1626, disable the DMA mapping feature temporarily to prevent exploitation. For SIMATIC CP 1628, limit local access to the system to prevent attackers with administrative privileges from causing a denial of service.

Correção

Improper Resource Release

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-06783
CVE-2023-37195

Produtos afetados

Simatic Cp 1604
Simatic Cp 1616
Simatic Cp 1623
Simatic Cp 1626
Simatic Cp 1628