Denial of service in Siemens Automation License Manager - CVE-2016-8563

 

Denial of service in Siemens Automation License Manager - CVE-2016-8563

Published: October 13, 2016 / Updated: October 14, 2016


Vulnerability identifier: #VU981
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-8563
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote unauthenticated user to cause DoS conditions on the target system.
The weakness is due to improper input validation. By sending a specially crafted packets to TCP port 4410, attackers can trigger the ALM service to crash. A manual restart is necessary to restore the normal system functionality.
Successful exploitation of the vulnerability leads to denial of service on the vulnerable system.

Affected software

Siemens Automation License Manager

How to mitigate CVE-2016-8563

Install version 5.3 SP3 Update 1.


External References

Related Security Bulletins