CVE-2023-37482

MEDIUM

Web Server - Info Disclosure

Title source: llm
STIX 2.1

Description

The login functionality of the web server in affected devices does not normalize the response times of login attempts. An unauthenticated remote attacker could exploit this side-channel information to distinguish between valid and invalid usernames.

Scores

CVSS v3 5.3
EPSS 0.0013
EPSS Percentile 32.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-203
Status published
Products (50)
Siemens/SIMATIC Drive Controller CPU 1504D TF V3.1.0 - V3.1.2
Siemens/SIMATIC Drive Controller CPU 1507D TF V3.1.0 - V3.1.2
Siemens/SIMATIC ET 200SP CPU 1510SP F-1 PN V3.1.0 - V3.1.2
Siemens/SIMATIC ET 200SP CPU 1510SP-1 PN V3.1.0 - V3.1.2
Siemens/SIMATIC ET 200SP CPU 1512SP F-1 PN V3.1.0 - V3.1.2
Siemens/SIMATIC ET 200SP CPU 1512SP-1 PN V3.1.0 - V3.1.2
Siemens/SIMATIC ET 200SP CPU 1514SP F-2 PN V3.1.0 - V3.1.2
Siemens/SIMATIC ET 200SP CPU 1514SP-2 PN V3.1.0 - V3.1.2
Siemens/SIMATIC ET 200SP CPU 1514SPT F-2 PN V3.1.0 - V3.1.2
Siemens/SIMATIC ET 200SP CPU 1514SPT-2 PN V3.1.0 - V3.1.2
... and 40 more
Published Feb 11, 2025
Tracked Since Feb 18, 2026