CVE-2023-4418: High severity SICK Lms531 Firmware vulnerability
A remote unprivileged attacker can sent multiple packages to the LMS5xx to disrupt its availability through a TCP SYN-based denial-of-service (DDoS) attack. By exploiting this vulnerability, an attacker can flood the targeted LMS5xx with a high volume of TCP SYN requests, overwhelming its resources and causing it to become unresponsive or unavailable for legitimate users.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-4418?
CVE-2023-4418 is a vulnerability that allows a remote unprivileged attacker to disrupt the availability of the LMS5xx device through a TCP SYN-based denial-of-service (DDoS) attack.
How does CVE-2023-4418 work?
CVE-2023-4418 allows an attacker to flood the targeted LMS5xx device with a high volume of TCP SYN requests, overwhelming its resources.
What is the severity of CVE-2023-4418?
CVE-2023-4418 has a severity rating of 7.5 out of 10, making it a high-risk vulnerability.
Which products are affected by CVE-2023-4418?
The following products are affected by CVE-2023-4418: Sick Lms531 Firmware, Sick Lms511 Firmware, and Sick Lms500 Firmware.
How can I fix CVE-2023-4418?
To fix CVE-2023-4418, it is recommended to apply the latest firmware updates provided by Sick.