CVE-2023-51440: High severity siemens simatic cp 343-1 advanced vulnerability
A vulnerability has been identified in SIMATIC CP 343-1 (6GK7343-1EX30-0XE0) (All versions), SIMATIC CP 343-1 Lean (6GK7343-1CX10-0XE0) (All versions), SIPLUS NET CP 343-1 (6AG1343-1EX30-7XE0) (All versions), SIPLUS NET CP 343-1 Lean (6AG1343-1CX10-2XE0) (All versions). Affected products incorrectly validate TCP sequence numbers. This could allow an unauthenticated remote attacker to create a denial of service condition by injecting spoofed TCP RST packets.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-51440?
CVE-2023-51440 has not been assigned a specific severity rating but is considered a significant vulnerability affecting multiple Siemens products.
Who is affected by CVE-2023-51440?
CVE-2023-51440 affects all versions of the SIMATIC CP 343-1 and SIMATIC CP 343-1 Lean, along with SIPLUS NET CP 343-1 and SIPLUS NET CP 343-1 Lean.
How do I fix CVE-2023-51440?
To address CVE-2023-51440, you should consult the vendor for mitigation instructions and apply any recommended firmware updates or patches.
What products are impacted by CVE-2023-51440?
CVE-2023-51440 impacts the Siemens SIMATIC CP 343-1, SIMATIC CP 343-1 Lean, SIPLUS NET CP 343-1, and SIPLUS NET CP 343-1 Lean across all versions.
What actions should organizations take regarding CVE-2023-51440?
Organizations should assess their use of affected Siemens products and apply updates or mitigations as recommended by Siemens.