CVE-2023-36521
Published: Jul 11, 2023
Modified: Nov 21, 2024
CVSS v3.1
8.6
Description
A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3.4), SIMATIC MV540 S (All versions < V3.3.4), SIMATIC MV550 H (All versions < V3.3.4), SIMATIC MV550 S (All versions < V3.3.4), SIMATIC MV560 U (All versions < V3.3.4), SIMATIC MV560 X (All versions < V3.3.4). The result synchronization server of the affected products contains a vulnerability that may lead to a denial of service condition. An attacker may cause a denial of service situation of all socket-based communication of the affected products if the result server is enabled.
| Vendor | Product | Versions |
|---|---|---|
Siemens | SIMATIC MV540 H | affected All versions < V3.3.4 |
Siemens | SIMATIC MV540 S | affected All versions < V3.3.4 |
Siemens | SIMATIC MV550 H | affected All versions < V3.3.4 |
Siemens | SIMATIC MV550 S | affected All versions < V3.3.4 |
Siemens | SIMATIC MV560 U | affected All versions < V3.3.4 |
Siemens | SIMATIC MV560 X | affected All versions < V3.3.4 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now