Vulnerability Details CVE-2023-35921
A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3.4), SIMATIC MV540 S (All versions < V3.3.4), SIMATIC MV550 H (All versions < V3.3.4), SIMATIC MV550 S (All versions < V3.3.4), SIMATIC MV560 U (All versions < V3.3.4), SIMATIC MV560 X (All versions < V3.3.4). Affected devices cannot properly process specially crafted Ethernet frames sent to the devices. This could allow an unauthenticated remote attacker to cause a denial of service condition. The affected devices must be restarted manually.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 71.8%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2023-35921
-
cpe:2.3:h:siemens:simatic_mv540_h:-
-
cpe:2.3:h:siemens:simatic_mv540_s:-
-
cpe:2.3:h:siemens:simatic_mv550_h:-
-
cpe:2.3:h:siemens:simatic_mv550_s:-
-
cpe:2.3:h:siemens:simatic_mv560_u:-
-
cpe:2.3:h:siemens:simatic_mv560_x:-
-
cpe:2.3:o:siemens:simatic_mv540_h_firmware:3.3
-
cpe:2.3:o:siemens:simatic_mv540_s_firmware:3.3
-
cpe:2.3:o:siemens:simatic_mv550_h_firmware:3.3
-
cpe:2.3:o:siemens:simatic_mv550_s_firmware:3.3
-
cpe:2.3:o:siemens:simatic_mv560_u_firmware:3.3
-
cpe:2.3:o:siemens:simatic_mv560_x_firmware:3.3