CVE-2023-37194: Medium severity siemens cp 1604 firmware vulnerability
A vulnerability has been identified in SIMATIC CP 1604 (All versions), SIMATIC CP 1616 (All versions), SIMATIC CP 1623 (All versions), SIMATIC CP 1626 (All versions), SIMATIC CP 1628 (All versions). The kernel memory of affected devices is exposed to user-mode via direct memory access (DMA) which could allow a local attacker with administrative privileges to execute arbitrary code on the host system without any restrictions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-37194?
The severity of CVE-2023-37194 is medium with a severity value of 6.7.
Which software versions are affected by CVE-2023-37194?
SIMATIC CP 1604 (All versions), SIMATIC CP 1616 (All versions), SIMATIC CP 1623 (All versions), SIMATIC CP 1626 (All versions), SIMATIC CP 1628 (All versions) are affected by CVE-2023-37194.
What is the vulnerability in CVE-2023-37194?
The vulnerability in CVE-2023-37194 is that the kernel memory of affected devices is exposed to user-mode via direct memory access (DMA).
How can I fix CVE-2023-37194?
Siemens has released a firmware update to fix CVE-2023-37194. Please refer to the Siemens product security advisory for more information.