CVE-2024-23814

MEDIUM

Siemens SIMATIC and SIDOOR Devices - Unauthenticated Denial of Service via ICMP Fragment Reassembly

Title source: llm
STIX 2.1

Description

The integrated ICMP service of the network stack of affected devices can be forced to exhaust its available memory resources when receiving specially crafted messages targeting IP fragment re-assembly. This could allow an unauthenticated remote attacker to cause a temporary denial of service condition of the ICMP service, other communication services are not affected. Affected devices will resume normal operation after the attack terminates.

Scores

CVSS v3 5.3
EPSS 0.0023
EPSS Percentile 45.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (50)
Siemens/SIDOOR ATD430W
Siemens/SIDOOR ATE530G COATED
Siemens/SIDOOR ATE530S COATED
Siemens/SIMATIC CFU DIQ < V2.0.0
Siemens/SIMATIC CFU PA < V2.0
Siemens/SIMATIC CFU PA < V2.0.0
Siemens/SIMATIC ET 200AL IM 157-1 PN
Siemens/SIMATIC ET 200M IM 153-4 PN IO HF
Siemens/SIMATIC ET 200M IM 153-4 PN IO ST
Siemens/SIMATIC ET 200MP IM 155-5 PN BA
... and 40 more
Published Feb 11, 2025
Tracked Since Feb 18, 2026