Resource exhaustion in Siemens products - CVE-2023-35921
Published: July 13, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when processing specially crafted Ethernet frames. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
SIMATIC MV540 S
SIMATIC MV550 H
SIMATIC MV550 S
SIMATIC MV560 U
SIMATIC MV560 X
How to mitigate CVE-2023-35921
SIMATIC MV540 S - update to 3.3.4
SIMATIC MV550 H - update to 3.3.4
SIMATIC MV550 S - update to 3.3.4
SIMATIC MV560 U - update to 3.3.4
SIMATIC MV560 X - update to 3.3.4