CVE-2023-4418

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
24/08/2023
Last modified:
30/08/2023

Description

A remote unprivileged attacker can sent multiple packages to the LMS5xx to disrupt its availability through a TCP SYN-based denial-of-service (DDoS) attack. <br /> By exploiting this vulnerability, an attacker can flood the targeted LMS5xx with a high volume of TCP SYN requests, overwhelming its resources and causing it to become unresponsive or unavailable for legitimate users.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:sick:lms531_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sick:lms531:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:lms511_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sick:lms511:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:lms500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sick:lms500:-:*:*:*:*:*:*:*