PT-2023-6080 · Siemens · Simatic Cp 1623+4
CVE-2023-37195
·
Publicado
2023-10-10
·
Atualizado
2023-10-16
CVSS v2.0
4.9
Média
| Vetor | AV:L/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
SIMATIC CP 1604 versions all
SIMATIC CP 1616 versions all
SIMATIC CP 1623 versions all
SIMATIC CP 1626 versions all
SIMATIC CP 1628 versions all
Description
The issue is related to insufficient control of access to memory DMA, which could allow an attacker to cause a denial of service situation on the host. This can be exploited by local attackers with administrative privileges. A physical power cycle is required to restore system functionality.
Recommendations
For SIMATIC CP 1604, consider restricting access to the DMA mapping functionality until a patch is available.
For SIMATIC CP 1616, avoid using administrative privileges for local attackers to minimize the risk of exploitation.
For SIMATIC CP 1623, restrict the use of continuous DMA requests to prevent denial of service situations.
For SIMATIC CP 1626, disable the DMA mapping feature temporarily to prevent exploitation.
For SIMATIC CP 1628, limit local access to the system to prevent attackers with administrative privileges from causing a denial of service.
Correção
Improper Resource Release
Resource Exhaustion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Simatic Cp 1604
Simatic Cp 1616
Simatic Cp 1623
Simatic Cp 1626
Simatic Cp 1628