A remote unprivileged attacker can sent multiple packages to the LMS5xx to disrupt its availability through a TCP SYN-based denial-of-service (DDoS) attack.
By exploiting this vulnerability, an attacker can flood the targeted LMS5xx with a high volume of TCP SYN requests, overwhelming its resources and causing it to become unresponsive or unavailable for legitimate users.
Fixes

Solution

No solution given by the vendor.


Workaround

Please make sure that you apply general security practices when operating the LMS5xx. The following General Security Practices and Operating Guidelines could mitigate the associated security risk. It is also recommended to apply the security practices listed in the LMS5xx hardening guide.

History

Mon, 09 Dec 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Sick lms5xx
CPEs cpe:2.3:h:sick_ag:lms5xx:*:*:*:*:*:*:*:* cpe:2.3:h:sick:lms5xx:*:*:*:*:*:*:*:*
Vendors & Products Sick Ag
Sick Ag lms5xx
Sick lms5xx

Wed, 02 Oct 2024 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Sick Ag
Sick Ag lms5xx
CPEs cpe:2.3:h:sick_ag:lms5xx:*:*:*:*:*:*:*:*
Vendors & Products Sick Ag
Sick Ag lms5xx
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: SICK AG

Published:

Updated: 2024-12-09T14:12:17.603Z

Reserved: 2023-08-18T13:09:11.346Z

Link: CVE-2023-4418

cve-icon Vulnrichment

Updated: 2024-08-02T07:24:04.985Z

cve-icon NVD

Status : Modified

Published: 2023-08-24T19:15:42.890

Modified: 2024-11-21T08:35:06.343

Link: CVE-2023-4418

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.