Input validation error in Siemens products - CVE-2023-45623
Published: February 14, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in the Wi-Fi Uplink service accessed via the PAPI protocol. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.
Affected software
SCALANCE W1750D (ROW)
SCALANCE W1750D (USA)
Aruba InstantOS
ArubaOS (AOS)
How to mitigate CVE-2023-45623
ArubaOS (AOS) - addressed in versions 10.4.0.3, 10.5.0.1