5.3

CVE-2023-43775

Denial-of-service vulnerability in the web server of the Eaton SMP Gateway allows 

attacker to potentially force an unexpected restart of the automation platform, impacting the availability of the product. In rare situations, the issue could cause
the SMP device to restart in Safe Mode or Max Safe Mode. When in Max Safe Mode, the product is
not vulnerable anymore.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
EatonSmp Sg-4260 Firmware Version >= 8.0 < 8.0r9
   EatonSmp Sg-4260 Version-
EatonSmp Sg-4260 Firmware Version >= 8.1 < 8.1r5
   EatonSmp Sg-4260 Version-
EatonSmp Sg-4260 Firmware Version >= 8.2 < 8.2r4
   EatonSmp Sg-4260 Version-
EatonSmp Sg-4250 Firmware Version >= 8.0 < 8.0r9
   EatonSmp Sg-4250 Version-
EatonSmp Sg-4250 Firmware Version >= 8.1 < 8.1r5
   EatonSmp Sg-4250 Version-
EatonSmp Sg-4250 Firmware Version >= 8.2 < 8.2r4
   EatonSmp Sg-4250 Version-
EatonSmp Sg-4250 Firmware Version7.0
   EatonSmp Sg-4250 Version-
EatonSmp Sg-4250 Firmware Version7.1
   EatonSmp Sg-4250 Version-
EatonSmp Sg-4250 Firmware Version7.2
   EatonSmp Sg-4250 Version-
EatonSmp 4/dp Firmware Version >= 8.0 < 8.0r9
   EatonSmp 4/dp Version-
EatonSmp 4/dp Firmware Version >= 8.1 < 8.1r5
   EatonSmp 4/dp Version-
EatonSmp 4/dp Firmware Version >= 8.2 < 8.2r4
   EatonSmp 4/dp Version-
EatonSmp 4/dp Firmware Version6.3
   EatonSmp 4/dp Version-
EatonSmp 4/dp Firmware Version7.0
   EatonSmp 4/dp Version-
EatonSmp 4/dp Firmware Version7.1
   EatonSmp 4/dp Version-
EatonSmp 4/dp Firmware Version7.2
   EatonSmp 4/dp Version-
EatonSmp 16 Firmware Version >= 8.0 < 8.0r9
   EatonSmp 16 Version-
EatonSmp 16 Firmware Version6.3
   EatonSmp 16 Version-
EatonSmp 16 Firmware Version7.0
   EatonSmp 16 Version-
EatonSmp 16 Firmware Version7.1
   EatonSmp 16 Version-
EatonSmp 16 Firmware Version7.2
   EatonSmp 16 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.05% 0.157
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CybersecurityCOE@eaton.com 4.7 2.8 1.4
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.