CVE-2023-6408
published 2024-02-14CVE-2023-6408: CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a denial of service and…
PriorityP340high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.32%
23.8th percentile
CWE-924: Improper Enforcement of Message Integrity During Transmission in a
Communication Channel vulnerability exists that could cause a denial of service and loss of
confidentiality, integrity of controllers when conducting a Man in the Middle attack.
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | ecostruxure_control_expert | < 16.0 | 16.0 |
| schneider-electric | ecostruxure_process_expert | < 2023 | 2023 |
| schneider-electric | modicon_m340_bmxp341000_firmware | < 3.60 | 3.60 |
| schneider-electric | modicon_m340_bmxp341000h_firmware | < 3.60 | 3.60 |
| schneider-electric | modicon_m340_bmxp342000_firmware | < 3.60 | 3.60 |
| schneider-electric | modicon_m340_bmxp3420102_firmware | < 3.60 | 3.60 |
| schneider-electric | modicon_m340_bmxp3420102cl_firmware | < 3.60 | 3.60 |
| schneider-electric | modicon_m340_bmxp342010_firmware | < 3.60 | 3.60 |
| schneider-electric | modicon_m340_bmxp342020_firmware | < 3.60 | 3.60 |
| schneider-electric | modicon_m340_bmxp342020h_firmware | < 3.60 | 3.60 |
| schneider-electric | modicon_m340_bmxp3420302_firmware | < 3.60 | 3.60 |
| schneider-electric | modicon_m340_bmxp3420302cl_firmware | < 3.60 | 3.60 |
| schneider-electric | modicon_m340_bmxp3420302h_firmware | < 3.60 | 3.60 |
| schneider-electric | modicon_m340_bmxp342030_firmware | < 3.60 | 3.60 |
| schneider-electric | modicon_m340_bmxp342030h_firmware | < 3.60 | 3.60 |
| schneider-electric | modicon_m580_bmeh582040_firmware | < 4.20 | 4.20 |
| schneider-electric | modicon_m580_bmeh582040c_firmware | < 4.20 | 4.20 |
| schneider-electric | modicon_m580_bmeh582040s_firmware | < 4.21 | 4.21 |
| schneider-electric | modicon_m580_bmeh584040_firmware | < 4.20 | 4.20 |
| schneider-electric | modicon_m580_bmeh584040c_firmware | < 4.20 | 4.20 |
| schneider-electric | modicon_m580_bmeh584040s_firmware | < 4.21 | 4.21 |
| schneider-electric | modicon_m580_bmeh586040_firmware | < 4.20 | 4.20 |
| schneider-electric | modicon_m580_bmeh586040c_firmware | < 4.20 | 4.20 |
| schneider-electric | modicon_m580_bmeh586040s_firmware | < 4.21 | 4.21 |
| schneider-electric | modicon_m580_bmep581020_firmware | < 4.20 | 4.20 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mpx7-3w53-g6r5: CWE-924: Improper Enforcement of Message Integrity During Transmission in a
Communication Channel vulnerability exists that could cause a denial of se
ghsa_unreviewed·2024-02-14
CVE-2023-6408 [HIGH] CWE-924 GHSA-mpx7-3w53-g6r5: CWE-924: Improper Enforcement of Message Integrity During Transmission in a
Communication Channel vulnerability exists that could cause a denial of se
CWE-924: Improper Enforcement of Message Integrity During Transmission in a
Communication Channel vulnerability exists that could cause a denial of service and loss of
confidentiality, integrity of controllers when conducting a Man in the Middle attack.
OSV
libxpm vulnerabilities
osv·2023-10-23·CVSS 5.5
CVE-2023-43786 libxpm vulnerabilities
libxpm vulnerabilities
USN-6408-1 fixed several vulnerabilities in libXpm. This update provides
the corresponding update for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
Yair Mizrahi discovered that libXpm incorrectly handled certain malformed
XPM image files. If a user were tricked into opening a specially crafted
XPM image file, a remote attacker could possibly use this issue to consume
memory, leading to a denial of service. (CVE-2023-43786)
Yair Mizrahi discovered that libXpm incorrectly handled certain malformed
XPM image files. If a user were tricked into opening a specially crafted
XPM image file, a remote attacker could use this issue to cause libXpm to
crash, leading to a denial of service, or possibly execute arbitrary code.
(CVE-2023-43
CISA ICS
Schneider Electric EcoStruxure Control Expert, EcoStruxure Process Expert, and Modicon M340, M580 and M580 Safety PLCs
cisa_ics·2024-11-26·CVSS 8.1
[HIGH] Schneider Electric EcoStruxure Control Expert, EcoStruxure Process Expert, and Modicon M340, M580 and M580 Safety PLCs
ICS Advisory
##
Schneider Electric EcoStruxure Control Expert, EcoStruxure Process Expert, and Modicon M340, M580 and M580 Safety PLCs
Release DateNovember 26, 2024
Alert CodeICSA-24-331-03
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.1
- ATTENTION: Exploitable remotely
- Vendor: Schneider Electric
- Equipment: EcoStruxure Control Expert, EcoStruxure Process Expert and Modicon M340, M580 and M580 Safety PLCs
- Vulnerabilities: Improper Enforcement of Message Integrity During Transmission in a Communication Channel, Use of Hard-coded Credentials, Insufficiently Protected Credentials
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow a de
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-02-14
Published