If an attacker were to access memory locations of LS ELECTRIC XBC-DN32U with operating system version 01.80 that are outside of the communication buffer, the device stops operating. This could allow an attacker to cause a denial-of-service condition.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-12201 If an attacker were to access memory locations of LS ELECTRIC XBC-DN32U with operating system version 01.80 that are outside of the communication buffer, the device stops operating. This could allow an attacker to cause a denial-of-service condition.
Fixes

Solution

No solution given by the vendor.


Workaround

LS ELECTRIC is developing mitigations (to be released tentatively by the end of 2023) and recommends users follow the provided workarounds to reduce the risk of exploitation: * Restrict communication to the PLC to only trusted IP addresses and trusted devices by enabling the “Host Table” option in the configuration window of the PLC.

History

Thu, 16 Jan 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-01-16T21:56:59.978Z

Reserved: 2023-01-06T18:50:04.019Z

Link: CVE-2023-0103

cve-icon Vulnrichment

Updated: 2024-08-02T05:02:43.339Z

cve-icon NVD

Status : Modified

Published: 2023-02-15T18:15:11.590

Modified: 2024-11-21T07:36:33.523

Link: CVE-2023-0103

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.