CVE-2023-28831

Severity CVSS v4.0:
HIGH
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
12/09/2023
Last modified:
18/08/2025

Description

The OPC UA implementations (ANSI C and C++) in affected products contain an integer overflow vulnerability that could cause the application to run into an infinite loop during certificate validation.<br /> <br /> This could allow an unauthenticated remote attacker to create a denial of service condition by sending a specially crafted certificate.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:siemens:simatic_cloud_connect_7_cc712_firmware:*:*:*:*:*:*:*:* 2.2 (excluding)
cpe:2.3:h:siemens:simatic_cloud_connect_7_cc712:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_cloud_connect_7_cc716_firmware:*:*:*:*:*:*:*:* 2.2 (excluding)
cpe:2.3:h:siemens:simatic_cloud_connect_7_cc716:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_drive_controller_cpu_1504d_tf_firmware:*:*:*:*:*:*:*:* 2.2 (excluding)
cpe:2.3:h:siemens:simatic_drive_controller_cpu_1504d_tf:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_drive_controller_cpu_1507d_tf_firmware:*:*:*:*:*:*:*:* 2.9.7 (excluding)
cpe:2.3:h:siemens:simatic_drive_controller_cpu_1507d_tf:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_et_200sp_open_controller_cpu_firmware:*:*:*:*:*:*:*:* 2.9.7 (excluding)
cpe:2.3:h:siemens:simatic_et_200sp_open_controller_cpu:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_s7-1200_cpu_firmware:*:*:*:*:*:*:*:* 3.0.3 (excluding)
cpe:2.3:h:siemens:simatic_s7-1200_cpu:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_s7-1500_cpu_1510sp-1_pn_firmware:*:*:*:*:*:*:*:* 2.9.7 (excluding)
cpe:2.3:h:siemens:simatic_s7-1500_cpu_1510sp-1_pn:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_s7-1500_cpu_1510sp_f-1_pn_firmware:*:*:*:*:*:*:*:* 3.0.3 (excluding)