CVE-2023-49252: Input Validation
Published Jan 9, 2024
·Updated
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The affected application allows IP configuration change without authentication to the device. This could allow an attacker to cause denial of service condition.
Affected Software
2 affected components
All of the following
Siemens Simatic Cn 4100 Firmware<2.7
Siemens SIMATIC CN 4100
Remediation
Event History
Jan 9, 2024
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-49252?
CVE-2023-49252 has a high severity rating due to its potential to allow unauthorized IP configuration changes.
2
How do I fix CVE-2023-49252?
To fix CVE-2023-49252, update SIMATIC CN 4100 to version 2.7 or higher.
3
What types of attacks can exploit CVE-2023-49252?
CVE-2023-49252 can be exploited to cause a denial of service by allowing unauthorized changes to IP configuration.
4
Which versions of SIMATIC CN 4100 are affected by CVE-2023-49252?
CVE-2023-49252 affects all versions of SIMATIC CN 4100 prior to version 2.7.
5
Is authentication required to exploit CVE-2023-49252?
No, CVE-2023-49252 allows IP configuration changes without authentication, making it particularly vulnerable.