CVE-2023-4418
Severity CVSS v4.0:
Pending analysis
Type:
CWE-400
Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
24/08/2023
Last modified:
30/08/2023
Description
A remote unprivileged attacker can sent multiple packages to the LMS5xx to disrupt its availability through a TCP SYN-based denial-of-service (DDoS) attack. <br />
By exploiting this vulnerability, an attacker can flood the targeted LMS5xx with a high volume of TCP SYN requests, overwhelming its resources and causing it to become unresponsive or unavailable for legitimate users.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:sick:lms531_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:sick:lms531:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:sick:lms511_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:sick:lms511:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:sick:lms500_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:sick:lms500:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



