vendor:
Desigo PX
by:
LiquidWorm
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: Desigo PX
Affected Version From: 6.00
Affected Version To: 6.00.320
Patch Exists: YES
Related CWE: N/A
CPE: h:siemens:desigo_px
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: All
2019
Siemens Desigo PX 6.00 – Denial of Service (PoC)
The device contains a vulnerability that could allow an attacker to cause a denial of service condition on the device's web server by sending a specially crafted HTTP message to the web server port (tcp/80). The security vulnerability could be exploited by an attacker with network access to an affected device. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise the availability of the device's web service. While tesing, the device was rebooted after the attack.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update their devices to the latest version of the firmware.