5.3
CVE-2023-43775
- EPSS 0.67%
- Veröffentlicht 27.09.2023 15:19:34
- Zuletzt bearbeitet 21.11.2024 08:24:45
- Erkennungen
Security issue in SMP Gateway automation platform
Denial-of-service vulnerability in the web server of the Eaton SMP Gateway allows attacker to potentially force an unexpected restart of the automation platform, impacting the availability of the product. In rare situations, the issue could cause the SMP device to restart in Safe Mode or Max Safe Mode. When in Max Safe Mode, the product is not vulnerable anymore.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Eaton ≫ Smp Sg-4260 Firmware Version >= 8.0 < 8.0r9
Eaton ≫ Smp Sg-4260 Firmware Version >= 8.1 < 8.1r5
Eaton ≫ Smp Sg-4260 Firmware Version >= 8.2 < 8.2r4
Eaton ≫ Smp Sg-4250 Firmware Version >= 8.0 < 8.0r9
Eaton ≫ Smp Sg-4250 Firmware Version >= 8.1 < 8.1r5
Eaton ≫ Smp Sg-4250 Firmware Version >= 8.2 < 8.2r4
Eaton ≫ Smp Sg-4250 Firmware Version 7.0
Eaton ≫ Smp Sg-4250 Firmware Version 7.1
Eaton ≫ Smp Sg-4250 Firmware Version 7.2
Eaton ≫ Smp 4/dp Firmware Version >= 8.0 < 8.0r9
Eaton ≫ Smp 4/dp Firmware Version >= 8.1 < 8.1r5
Eaton ≫ Smp 4/dp Firmware Version >= 8.2 < 8.2r4
Eaton ≫ Smp 4/dp Firmware Version 6.3
Eaton ≫ Smp 4/dp Firmware Version 7.0
Eaton ≫ Smp 4/dp Firmware Version 7.1
Eaton ≫ Smp 4/dp Firmware Version 7.2
Eaton ≫ Smp 16 Firmware Version >= 8.0 < 8.0r9
Eaton ≫ Smp 16 Firmware Version 6.3
Eaton ≫ Smp 16 Firmware Version 7.0
Eaton ≫ Smp 16 Firmware Version 7.1
Eaton ≫ Smp 16 Firmware Version 7.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.67% | 0.469 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
|
| CybersecurityCOE@eaton.com | 4.7 | 2.8 | 1.4 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
|
CWE-400 Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
https://www.eaton.com/content/dam/eaton/company/news-insights/cybersecurity/security-bulletins/etn-va-2022-1008.pdf