First published: Thu Aug 24 2023(Updated: )
A remote unprivileged attacker can sent multiple packages to the LMS5xx to disrupt its availability through a TCP SYN-based denial-of-service (DDoS) attack. By exploiting this vulnerability, an attacker can flood the targeted LMS5xx with a high volume of TCP SYN requests, overwhelming its resources and causing it to become unresponsive or unavailable for legitimate users.
Credit: psirt@sick.de psirt@sick.de
Affected Software | Affected Version | How to fix |
---|---|---|
Sick Lms531 Firmware | ||
Sick Lms531 | ||
Sick Lms511 Firmware | ||
Sick Lms511 | ||
Sick Lms500 Firmware | ||
Sick Lms500 | ||
All of | ||
Sick Lms531 Firmware | ||
Sick Lms531 | ||
All of | ||
Sick Lms511 Firmware | ||
Sick Lms511 | ||
All of | ||
Sick Lms500 Firmware | ||
Sick Lms500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-4418 is a vulnerability that allows a remote unprivileged attacker to disrupt the availability of the LMS5xx device through a TCP SYN-based denial-of-service (DDoS) attack.
CVE-2023-4418 allows an attacker to flood the targeted LMS5xx device with a high volume of TCP SYN requests, overwhelming its resources.
CVE-2023-4418 has a severity rating of 7.5 out of 10, making it a high-risk vulnerability.
The following products are affected by CVE-2023-4418: Sick Lms531 Firmware, Sick Lms511 Firmware, and Sick Lms500 Firmware.
To fix CVE-2023-4418, it is recommended to apply the latest firmware updates provided by Sick.