ID

VAR-202406-0042


CVE

CVE-2023-50763


TITLE

Siemens TIM 1531 IRC infinite loop vulnerability

Trust: 0.6

sources: CNVD: CNVD-2024-26693

DESCRIPTION

A vulnerability has been identified in SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0) (All versions < V2.3), SIMATIC CP 1542SP-1 IRC (6GK7542-6VX00-0XE0) (All versions < V2.3), SIMATIC CP 1543SP-1 (6GK7543-6WX00-0XE0) (All versions < V2.3), SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL (6AG2542-6VX00-4XE0) (All versions < V2.3), SIPLUS ET 200SP CP 1543SP-1 ISEC (6AG1543-6WX00-7XE0) (All versions < V2.3), SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL (6AG2543-6WX00-4XE0) (All versions < V2.3), SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0) (All versions < V2.4.8), TIM 1531 IRC (6GK7543-1MX00-0XE0) (All versions < V2.4.8). The web server of affected products, if configured to allow the import of PKCS12 containers, could end up in an infinite loop when processing incomplete certificate chains. This could allow an authenticated remote attacker to create a denial of service condition by importing specially crafted PKCS12 containers. TIM 1531 IRC is a communication module for SIMATIC S7-1500, S7-400, S7-300

Trust: 1.44

sources: NVD: CVE-2023-50763 // CNVD: CNVD-2024-26693

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2024-26693

AFFECTED PRODUCTS

vendor:siemensmodel:siplus tim ircscope:eqversion:1531<v2.4.8

Trust: 0.6

vendor:siemensmodel:tim ircscope:eqversion:1531<v2.4.8

Trust: 0.6

sources: CNVD: CNVD-2024-26693

CVSS

SEVERITY

CVSSV2

CVSSV3

productcert@siemens.com: CVE-2023-50763
value: MEDIUM

Trust: 1.0

CNVD: CNVD-2024-26693
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2024-26693
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:L/AU:S/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

productcert@siemens.com: CVE-2023-50763
baseSeverity: MEDIUM
baseScore: 4.9
vectorString: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 1.2
impactScore: 3.6
version: 3.1

Trust: 1.0

sources: CNVD: CNVD-2024-26693 // NVD: CVE-2023-50763

PROBLEMTYPE DATA

problemtype:CWE-835

Trust: 1.0

sources: NVD: CVE-2023-50763

PATCH

title:Patch for Siemens TIM 1531 IRC infinite loop vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/555116

Trust: 0.6

sources: CNVD: CNVD-2024-26693

EXTERNAL IDS

db:SIEMENSid:SSA-337522

Trust: 1.6

db:NVDid:CVE-2023-50763

Trust: 1.6

db:SIEMENSid:SSA-139628

Trust: 1.0

db:SIEMENSid:SSA-625862

Trust: 1.0

db:CNVDid:CNVD-2024-26693

Trust: 0.6

sources: CNVD: CNVD-2024-26693 // NVD: CVE-2023-50763

REFERENCES

url:https://cert-portal.siemens.com/productcert/html/ssa-337522.html

Trust: 1.6

url:https://cert-portal.siemens.com/productcert/html/ssa-139628.html

Trust: 1.0

url:https://cert-portal.siemens.com/productcert/html/ssa-625862.html

Trust: 1.0

sources: CNVD: CNVD-2024-26693 // NVD: CVE-2023-50763

SOURCES

db:CNVDid:CNVD-2024-26693
db:NVDid:CVE-2023-50763

LAST UPDATE DATE

2024-08-14T13:12:54.921000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2024-26693date:2024-06-12T00:00:00
db:NVDid:CVE-2023-50763date:2024-06-11T13:54:12.057

SOURCES RELEASE DATE

db:CNVDid:CNVD-2024-26693date:2024-06-12T00:00:00
db:NVDid:CVE-2023-50763date:2024-06-11T12:15:13.763