Lucene search

K
cve[email protected]CVE-2023-5188
HistoryDec 05, 2023 - 8:15 a.m.

CVE-2023-5188

2023-12-0508:15:07
CWE-20
web.nvd.nist.gov
10
mms interpreter
wagoapprtu
vulnerability
denial-of-service
cve-2023-5188
nvd

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

38.6%

The MMS Interpreter of WagoAppRTU in versions below 1.4.6.0 which is used by the WAGO Telecontrol Configurator is vulnerable to malformed packets. An remote unauthenticated attacker could send specifically crafted packets that lead to a denial-of-service condition until restart of the affected device.

Affected configurations

NVD
Node
wagotelecontrol_configurator
OR
wagowagoapprtuRange<1.4.6.0

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Telecontrol Configurator",
    "vendor": "WAGO",
    "versions": [
      {
        "status": "affected",
        "version": "*"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "WagoAppRTU",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThan": "1.4.6.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  }
]

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

38.6%

Related for CVE-2023-5188