CVE-2023-37194
Published: Oct 10, 2023
Modified: Sep 19, 2024
CVSS v3.1
6.7
Description
A vulnerability has been identified in SIMATIC CP 1604 (All versions), SIMATIC CP 1616 (All versions), SIMATIC CP 1623 (All versions), SIMATIC CP 1626 (All versions), SIMATIC CP 1628 (All versions). The kernel memory of affected devices is exposed to user-mode via direct memory access (DMA) which could allow a local attacker with administrative privileges to execute arbitrary code on the host system without any restrictions.
| Vendor | Product | Versions |
|---|---|---|
Siemens | SIMATIC CP 1604 | affected All versions |
Siemens | SIMATIC CP 1616 | affected All versions |
Siemens | SIMATIC CP 1623 | affected All versions |
Siemens | SIMATIC CP 1626 | affected All versions |
Siemens | SIMATIC CP 1628 | affected All versions |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now