HIGH🇵🇱 Wersja polska

CVE-2023-4418

CVSS 7.5v3.1pub. 2023-08-24upd. 2024-11-21

A remote unprivileged attacker can sent multiple packages to the LMS5xx to disrupt its availability through a TCP SYN-based denial-of-service (DDoS) attack. By exploiting this vulnerability, an attacker can flood the targeted LMS5xx with a high volume of TCP SYN requests, overwhelming its resources and causing it to become unresponsive or unavailable for legitimate users.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Sick Lms500

    HW
    Sick
    all versions
  • Sick Lms500 Firmware

    OS
    Sick
    all versions
  • Sick Lms511

    HW
    Sick
    all versions
  • Sick Lms511 Firmware

    OS
    Sick
    all versions
  • Sick Lms531

    HW
    Sick
    all versions
  • Sick Lms531 Firmware

    OS
    Sick
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-4419CRITICAL9.8PL ✓same product

Zakodowane na stałe dane uwierzytelniające w SICK LMS5xx

CVE-2023-4420CRITICAL9.8PL ✓same product

Brak szyfrowania TLS w urządzeniach SICK LMS5xx — przechwycenie komunikacji

CVE-2023-31412HIGH7.5same product

The LMS5xx uses weak hash generation methods, resulting in the creation of insecure hashs. If an attacker mana...

CVE-2020-2075HIGH7.5same product

Platform mechanism AutoIP allows remote attackers to reboot the device via a crafted packet in SICK AG solutio...

CVE-2026-22907CRITICAL9.9PL ✓same vendor

Nieautoryzowany dostęp do systemu plików hosta w SICK TDC-X401GL