CVE-2023-52891
A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.5), SIMATIC Energy Manager PRO (All versions < V7.5), SIMATIC IPC DiagBase (All versions), SIMATIC IPC DiagMonitor (All versions), SIMIT V10 (All versions), SIMIT V11 (All versions < V11.1). Unified Automation .NET based OPC UA Server SDK before 3.2.2 used in Siemens products are affected by a similar vulnerability as documented in CVE-2023-27321 for the OPC Foundation UA .NET Standard implementation. A successful attack may lead to high load situation and memory exhaustion, and may block the server.
Published:Jul 9, 2024
Last Modified:Apr 15, 2026
EPS:Jul 9, 2024
EPSS Score:0.00116
CVSS Score:5.3
Affected Products
Vendor
Product
Action
Vendor
Siemens
Product
Simatic Energy Manager Basic
Siemens
Simatic Energy Manager Basic
Vendor
Siemens
Product
Simatic Energy Manager Pro
Siemens
Simatic Energy Manager Pro
Vendor
Siemens
Product
Simatic Ipc Diagbase
Siemens
Simatic Ipc Diagbase
Vendor
Siemens
Product
Simatic Ipc Diagmonitor
Siemens
Simatic Ipc Diagmonitor
Vendor
Siemens
Product
Simit V10
Siemens
Simit V10
Vendor
Siemens
Product
Simit V11
Siemens
Simit V11
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
