Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-97272
HistoryDec 13, 2023 - 12:00 a.m.

Unspecified Vulnerability in Siemens LOGO! BM (Base Module) Devices

2023-12-1300:00:00
China National Vulnerability Database
www.cnvd.org.cn
9
siemens logo! bm
vulnerability
electromagnetic fault
injection
custom certificate
communication
emulation
device security
susceptibility
automation
ca

AI Score

7.4

Confidence

Low

EPSS

0.001

Percentile

17.0%

Siemens LOGO! BM (Base Module) devices are used for basic small-scale automation tasks. An unspecified vulnerability exists in the Siemens LOGO! BM (Base Module) device due to the susceptibility of the affected device to electromagnetic fault injection. An attacker could exploit the vulnerability to allow injection of a public key for a custom created key pair, which is then signed by the product CA. Generating a custom certificate allows communication and emulation with any device of the same version.

AI Score

7.4

Confidence

Low

EPSS

0.001

Percentile

17.0%

Related for CNVD-2023-97272