2023-12-12 15:05:13 +00:00
{
"id" : "CVE-2023-38380" ,
"sourceIdentifier" : "productcert@siemens.com" ,
"published" : "2023-12-12T12:15:11.477" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-21T08:13:26.780" ,
2024-03-12 15:04:12 +00:00
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-12-12 15:05:13 +00:00
"descriptions" : [
{
"lang" : "en" ,
2024-06-11 14:03:59 +00:00
"value" : "A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.4.29), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions < V3.4.29), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions < V3.4.29), SIMATIC CP 1243-7 LTE (All versions < V3.4.29), SIMATIC CP 1243-8 IRC (6GK7243-8RX30-0XE0) (All versions < V3.4.29), SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0) (All versions < V2.3), SIMATIC CP 1542SP-1 IRC (6GK7542-6VX00-0XE0) (All versions < V2.3), SIMATIC CP 1543-1 (6GK7543-1AX00-0XE0) (All versions < V3.0.37), SIMATIC CP 1543SP-1 (6GK7543-6WX00-0XE0) (All versions < V2.3), SINAMICS S210 (6SL5...) (All versions >= V6.1 < V6.1 HF2), SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL (6AG2542-6VX00-4XE0) (All versions < V2.3), SIPLUS ET 200SP CP 1543SP-1 ISEC (6AG1543-6WX00-7XE0) (All versions < V2.3), SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL (6AG2543-6WX00-4XE0) (All versions < V2.3), SIPLUS NET CP 1543-1 (6AG1543-1AX00-2XE0) (All versions < V3.0.37). The webserver implementation of the affected products does not correctly release allocated memory after it has been used.\r\n\r\nAn attacker with network access could use this vulnerability to cause a denial-of-service condition in the webserver of the affected product."
2023-12-18 17:00:28 +00:00
} ,
{
"lang" : "es" ,
"value" : "Se ha identificado una vulnerabilidad en:\nSIMATIC CP 1242-7 V2 (incluidas las variantes SIPLUS) (todas las versiones), \nSIMATIC CP 1243-1 (incluidas las variantes SIPLUS) (todas las versiones), \nSIMATIC CP 1243-1 DNP3 (incluidas las variantes SIPLUS) ) (todas las versiones), \nSIMATIC CP 1243-1 IEC (incl. variantes SIPLUS) (todas las versiones), \nSIMATIC CP 1243-7 LTE (todas las versiones), \nSIMATIC CP 1243-8 IRC (todas las versiones), \nSIMATIC CP 1543-1 (Todas las versiones), \nSINAMICS S210 (6SL5...) (Todas las versiones >= V6.1 < V6.1 HF2), \nSIPLUS NET CP 1543-1 (Todas las versiones). \nLa implementaci\u00f3n del servidor web de los productos afectados no libera correctamente la memoria asignada una vez utilizada. Un atacante con acceso a la red podr\u00eda utilizar esta vulnerabilidad para provocar una condici\u00f3n de denegaci\u00f3n de servicio en el servidor web del producto afectado."
2023-12-12 15:05:13 +00:00
}
] ,
"metrics" : {
2024-07-14 02:06:08 +00:00
"cvssMetricV40" : [
{
"source" : "productcert@siemens.com" ,
2024-12-15 03:03:56 +00:00
"type" : "Primary" ,
2024-07-14 02:06:08 +00:00
"cvssData" : {
"version" : "4.0" ,
"vectorString" : "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 8.7 ,
"baseSeverity" : "HIGH" ,
2024-07-14 02:06:08 +00:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"attackRequirements" : "NONE" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"vulnerableSystemConfidentiality" : "NONE" ,
"vulnerableSystemIntegrity" : "NONE" ,
"vulnerableSystemAvailability" : "HIGH" ,
"subsequentSystemConfidentiality" : "NONE" ,
"subsequentSystemIntegrity" : "NONE" ,
"subsequentSystemAvailability" : "NONE" ,
"exploitMaturity" : "NOT_DEFINED" ,
"confidentialityRequirements" : "NOT_DEFINED" ,
"integrityRequirements" : "NOT_DEFINED" ,
"availabilityRequirements" : "NOT_DEFINED" ,
"modifiedAttackVector" : "NOT_DEFINED" ,
"modifiedAttackComplexity" : "NOT_DEFINED" ,
"modifiedAttackRequirements" : "NOT_DEFINED" ,
"modifiedPrivilegesRequired" : "NOT_DEFINED" ,
"modifiedUserInteraction" : "NOT_DEFINED" ,
"modifiedVulnerableSystemConfidentiality" : "NOT_DEFINED" ,
"modifiedVulnerableSystemIntegrity" : "NOT_DEFINED" ,
"modifiedVulnerableSystemAvailability" : "NOT_DEFINED" ,
"modifiedSubsequentSystemConfidentiality" : "NOT_DEFINED" ,
"modifiedSubsequentSystemIntegrity" : "NOT_DEFINED" ,
"modifiedSubsequentSystemAvailability" : "NOT_DEFINED" ,
"safety" : "NOT_DEFINED" ,
"automatable" : "NOT_DEFINED" ,
"recovery" : "NOT_DEFINED" ,
"valueDensity" : "NOT_DEFINED" ,
"vulnerabilityResponseEffort" : "NOT_DEFINED" ,
2024-12-08 03:06:42 +00:00
"providerUrgency" : "NOT_DEFINED"
2024-07-14 02:06:08 +00:00
}
}
] ,
2023-12-12 15:05:13 +00:00
"cvssMetricV31" : [
{
"source" : "productcert@siemens.com" ,
2024-12-15 03:03:56 +00:00
"type" : "Primary" ,
2023-12-12 15:05:13 +00:00
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 7.5 ,
"baseSeverity" : "HIGH" ,
2023-12-12 15:05:13 +00:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "HIGH"
2023-12-12 15:05:13 +00:00
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 3.6
}
]
} ,
"weaknesses" : [
{
2024-12-08 03:06:42 +00:00
"source" : "productcert@siemens.com" ,
"type" : "Secondary" ,
2023-12-12 15:05:13 +00:00
"description" : [
{
"lang" : "en" ,
"value" : "CWE-401"
}
]
2023-12-18 17:00:28 +00:00
} ,
{
2024-12-08 03:06:42 +00:00
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
2023-12-18 17:00:28 +00:00
"description" : [
{
"lang" : "en" ,
"value" : "CWE-401"
}
]
}
] ,
"configurations" : [
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:6gk7243-8rx30-0xe0_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "BBBD0600-DB41-4DE8-97FC-2D180DA1406F"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:6gk7243-8rx30-0xe0:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A50A52E7-D8FE-4071-99B3-3652B0892D07"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:6gk7543-1ax00-0xe0_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "EF7C15EC-3C83-434B-A313-9035302EEF87"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:6gk7543-1ax00-0xe0:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E42E7B79-A3D2-4AAC-80E2-7E5C19A72CC5"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:6ag1543-1ax00-2xe0_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9373F60E-03D0-4EB2-9774-6479A8F342C7"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:6ag1543-1ax00-2xe0:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F9063778-2B5F-4A32-83C8-6CEB9EE8F9C0"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:simatic_cp_1242-7_v2_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "66A2C7F2-F787-4770-8F56-E2AFF1AFD780"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:simatic_cp_1242-7_v2:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "29D4C72C-4E84-4563-9D66-5C641AB996BA"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:simatic_cp_1243-1_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "373B769D-0E60-4362-BAE1-90BA6E0B211C"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:simatic_cp_1243-1:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CA9BB25C-D5E3-43DE-8C73-06BDC43CA960"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:simatic_cp_1243-1_dnp3_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1158D559-2A46-4BE4-B16E-C2789AD3C60E"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:simatic_cp_1243-1_dnp3:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2FFBFB96-1A35-4724-831B-68E3A9C32921"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:simatic_cp_1243-1_iec_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1C3E8B50-07E9-4697-B42D-86B9BE942553"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:simatic_cp_1243-1_iec:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "DFE96226-A2DF-4A9E-8CBB-8D7CF328E404"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:simatic_cp_1243-7_lte_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7FC29937-7A70-4A9F-89F8-8D17E285C225"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:simatic_cp_1243-7_lte:*:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "BAFC3319-F07C-4784-9873-3E1907FE3080"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:sinamics_s210_firmware:5.1:-:*:*:*:*:*:*" ,
"matchCriteriaId" : "BEBF14B3-65A0-41E9-B99C-D88548F307CD"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:sinamics_s210_firmware:5.1:sp1:*:*:*:*:*:*" ,
"matchCriteriaId" : "F151297C-3097-483F-98B5-0261BD547421"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:sinamics_s210_firmware:5.1:sp1_hotfix8:*:*:*:*:*:*" ,
"matchCriteriaId" : "4CEAB952-BBF0-4585-8F12-F25A192FAA1B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:sinamics_s210_firmware:5.2:-:*:*:*:*:*:*" ,
"matchCriteriaId" : "7F4D3F85-4CA5-438E-955E-C039F7DE91B1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:sinamics_s210_firmware:5.2:hotfix2:*:*:*:*:*:*" ,
"matchCriteriaId" : "59608DD3-87C3-4ED1-B0C2-AFD31A7A70A3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:sinamics_s210_firmware:5.2:hotfix5:*:*:*:*:*:*" ,
"matchCriteriaId" : "EA3D3D7E-CB48-4B8D-8101-CB0DADEEC0B1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:sinamics_s210_firmware:5.2:hotfix6:*:*:*:*:*:*" ,
"matchCriteriaId" : "6F8FC52F-3648-410B-8BCB-76129ABC0D4D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:sinamics_s210_firmware:5.2:hotfix7:*:*:*:*:*:*" ,
"matchCriteriaId" : "59BDCF31-2D94-4D7D-9EC8-60726B10DFC7"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:sinamics_s210_firmware:5.2:sp3:*:*:*:*:*:*" ,
"matchCriteriaId" : "D62C3EEA-000C-41CD-8264-4A4B6AE1BAD2"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:sinamics_s210_firmware:5.2:sp3_hotfix3:*:*:*:*:*:*" ,
"matchCriteriaId" : "EF00EE34-1A68-40F0-A9FC-FBBF268C6400"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:sinamics_s210_firmware:5.2:sp3_hotfix5:*:*:*:*:*:*" ,
"matchCriteriaId" : "C6BB896A-8C42-416E-AE03-D5A0E122BA79"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:sinamics_s210_firmware:5.2:sp3_hotfix6:*:*:*:*:*:*" ,
"matchCriteriaId" : "B18F1100-8157-4E99-AB22-BF51EB1663B3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:sinamics_s210_firmware:5.2:sp3_hotfix9:*:*:*:*:*:*" ,
"matchCriteriaId" : "AA9B1D54-E3A0-4EFF-8EB2-A52B8E1F117F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:sinamics_s210_firmware:6.1:-:*:*:*:*:*:*" ,
"matchCriteriaId" : "E509394F-9987-41D2-A866-68479FF39DCB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:sinamics_s210_firmware:6.1:hotfix1:*:*:*:*:*:*" ,
"matchCriteriaId" : "2DEB162B-6579-4280-9BCC-403C1B351002"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:sinamics_s210:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7BFA8FB3-12A9-4D2E-BCFD-C66313521C80"
}
]
}
]
2023-12-12 15:05:13 +00:00
}
] ,
"references" : [
2024-06-11 14:03:59 +00:00
{
"url" : "https://cert-portal.siemens.com/productcert/html/ssa-139628.html" ,
"source" : "productcert@siemens.com"
} ,
{
"url" : "https://cert-portal.siemens.com/productcert/html/ssa-625862.html" ,
"source" : "productcert@siemens.com"
} ,
2024-03-12 15:04:12 +00:00
{
"url" : "https://cert-portal.siemens.com/productcert/html/ssa-693975.html" ,
"source" : "productcert@siemens.com"
} ,
2023-12-12 15:05:13 +00:00
{
"url" : "https://cert-portal.siemens.com/productcert/pdf/ssa-693975.pdf" ,
2023-12-18 17:00:28 +00:00
"source" : "productcert@siemens.com" ,
"tags" : [
"Vendor Advisory"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://cert-portal.siemens.com/productcert/html/ssa-139628.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://cert-portal.siemens.com/productcert/html/ssa-625862.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://cert-portal.siemens.com/productcert/html/ssa-693975.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://cert-portal.siemens.com/productcert/pdf/ssa-693975.pdf" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
2023-12-12 15:05:13 +00:00
}
]
}