CVE-2024-23814
published 2025-02-11CVE-2024-23814: The integrated ICMP service of the network stack of affected devices can be forced to exhaust its available memory resources when receiving specially crafted…
PriorityP431medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.60%
44.7th percentile
The integrated ICMP service of the network stack of affected devices can be forced to exhaust its available memory resources when receiving specially crafted messages targeting IP fragment re-assembly. This could allow an unauthenticated remote attacker to cause a temporary denial of service condition of the ICMP service, other communication services are not affected. Affected devices will resume normal operation after the attack terminates.
Affected
136 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | sidoor_atd430w | < * | * |
| siemens | sidoor_ate530g_coated | < * | * |
| siemens | sidoor_ate530s_coated | < * | * |
| siemens | simatic_cfu_diq | < V2.0.0 | V2.0.0 |
| siemens | simatic_cfu_pa | < V2.0.0 | V2.0.0 |
| siemens | simatic_cfu_pa | < V2.0 | V2.0 |
| siemens | simatic_et_200al_im_157-1_pn | < * | * |
| siemens | simatic_et_200m_im_153-4_pn_io_hf | < * | * |
| siemens | simatic_et_200m_im_153-4_pn_io_st | < * | * |
| siemens | simatic_et_200mp_im_155-5_pn_ba | < * | * |
| siemens | simatic_et_200mp_im_155-5_pn_hf | < * | * |
| siemens | simatic_et_200mp_im_155-5_pn_st | < * | * |
| siemens | simatic_et_200pro_im_154-3_pn_hf | < * | * |
| siemens | simatic_et_200pro_im_154-4_pn_hf | < * | * |
| siemens | simatic_et_200pro_im_154-8_pn_dp_cpu | < * | * |
| siemens | simatic_et_200pro_im_154-8f_pn_dp_cpu | < * | * |
| siemens | simatic_et_200pro_im_154-8fx_pn_dp_cpu | < * | * |
| siemens | simatic_et_200s_im_151-3_pn_fo | < * | * |
| siemens | simatic_et_200s_im_151-3_pn_hf | < * | * |
| siemens | simatic_et_200s_im_151-3_pn_hs | < * | * |
| siemens | simatic_et_200s_im_151-3_pn_st | < * | * |
| siemens | simatic_et_200s_im_151-8_pn_dp_cpu | < * | * |
| siemens | simatic_et_200s_im_151-8f_pn_dp_cpu | < * | * |
| siemens | simatic_et_200sp_cpu_1510sp-1_pn | < * | * |
| siemens | simatic_et_200sp_cpu_1510sp_f-1_pn | < * | * |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMOCODE, SIMATIC, SIPLUS, SIDOOR, SIWAREX
cisa_ics·2025-04-15
Siemens SIMOCODE, SIMATIC, SIPLUS, SIDOOR, SIWAREX
ICS Advisory
##
Siemens SIMOCODE, SIMATIC, SIPLUS, SIDOOR, SIWAREX
Release DateApril 15, 2025
Alert CodeICSA-25-105-03
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 6.9
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMOCODE, SIMATIC, SIPLUS, SIDOOR, SIWAREX
- Vulnerability: Uncontrolled Resource Consumption
## 2. RISK EVA
CISA ICS
Siemens SCALANCE W700
cisa_ics·2025-02-13
Siemens SCALANCE W700
ICS Advisory
##
Siemens SCALANCE W700
Release DateFebruary 13, 2025
Alert CodeICSA-25-044-09
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE W700
- Vulnerabilities: Double Free, Improper Restriction of Communication Channel to Intended Endpoints, Improper Resource Sh
GHSA
GHSA-gx9r-288j-7947: A vulnerability has been identified in SCALANCE WAB762-1 (6GK5762-1AJ00-6AA0) (All versions < V3
ghsa_unreviewed·2025-02-11
CVE-2024-23814 [MEDIUM] CWE-400 GHSA-gx9r-288j-7947: A vulnerability has been identified in SCALANCE WAB762-1 (6GK5762-1AJ00-6AA0) (All versions < V3
A vulnerability has been identified in SCALANCE WAB762-1 (6GK5762-1AJ00-6AA0) (All versions < V3.0.0), SCALANCE WAM763-1 (6GK5763-1AL00-7DA0) (All versions < V3.0.0), SCALANCE WAM763-1 (ME) (6GK5763-1AL00-7DC0) (All versions < V3.0.0), SCALANCE WAM763-1 (US) (6GK5763-1AL00-7DB0) (All versions < V3.0.0), SCALANCE WAM766-1 (6GK5766-1GE00-7DA0) (All versions < V3.0.0), SCALANCE WAM766-1 (ME) (6GK5766-1GE00-7DC0) (All versions < V3.0.0), SCALANCE WAM766-1 (US) (6GK5766-1GE00-7DB0) (All versions < V3.0.0), SCALANCE WAM766-1 EEC (6GK5766-1GE00-7TA0) (All versions < V3.0.0), SCALANCE WAM766-1 EEC (ME) (6GK5766-1GE00-7TC0) (All versions < V3.0.0), SCALANCE WAM766-1 EEC (US) (6GK5766-1GE00-7TB0) (All versions < V3.0.0), SCALANCE WUB762-1 (6GK5762-1AJ00-1AA0) (All versions < V3.0.0), SCALANCE WUB762
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-02-11
Published