CVE-2024-23814 Information

Description

A vulnerability has been identified in SCALANCE WAB762-1 (6GK5762-1AJ00-6AA0) (All versions < V3.0.0) SCALANCE WAM763-1 (6GK5763-1AL00-7DA0) (All versions < V3.0.0) SCALANCE WAM763-1 (ME) (6GK5763-1AL00-7DC0) (All versions < V3.0.0) SCALANCE WAM763-1 (US) (6GK5763-1AL00-7DB0) (All versions < V3.0.0) SCALANCE WAM766-1 (6GK5766-1GE00-7DA0) (All versions < V3.0.0) SCALANCE WAM766-1 (ME) (6GK5766-1GE00-7DC0) (All versions < V3.0.0) SCALANCE WAM766-1 (US) (6GK5766-1GE00-7DB0) (All versions < V3.0.0) SCALANCE WAM766-1 EEC (6GK5766-1GE00-7TA0) (All versions < V3.0.0) SCALANCE WAM766-1 EEC (ME) (6GK5766-1GE00-7TC0) (All versions < V3.0.0) SCALANCE WAM766-1 EEC (US) (6GK5766-1GE00-7TB0) (All versions < V3.0.0) SCALANCE WUB762-1 (6GK5762-1AJ00-1AA0) (All versions < V3.0.0) SCALANCE WUB762-1 iFeatures (6GK5762-1AJ00-2AA0) (All versions < V3.0.0) SCALANCE WUM763-1 (6GK5763-1AL00-3AA0) (All versions < V3.0.0) SCALANCE WUM763-1 (6GK5763-1AL00-3DA0) (All versions < V3.0.0) SCALANCE WUM763-1 (US) (6GK5763-1AL00-3AB0) (All versions < V3.0.0) SCALANCE WUM763-1 (US) (6GK5763-1AL00-3DB0) (All versions < V3.0.0) SCALANCE WUM766-1 (6GK5766-1GE00-3DA0) (All versions < V3.0.0) SCALANCE WUM766-1 (ME) (6GK5766-1GE00-3DC0) (All versions < V3.0.0) SCALANCE WUM766-1 (USA) (6GK5766-1GE00-3DB0) (All versions < V3.0.0). The integrated ICMP service of the network stack of affected devices can be forced to exhaust its available memory resources when receiving specially crafted messages targeting IP fragment re-assembly. This could allow an unauthenticated remote attacker to cause a temporary denial of service condition of the ICMP service other communication services are not affected. Affected devices will resume normal operation after the attack terminates.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Reference

https://cert-portal.siemens.com/productcert/html/ssa-769027.html

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

NONE

Base Score

LOW

Base Severity

5.3

Share on: