IM
IronMonkey Threat Research

CVE-2023-5915 MEDIUM

Published: 2023-12-01 | Last Modified: 2024-11-21 | Status: Modified

Description

A vulnerability of Uncontrolled Resource Consumption has been identified in STARDOM provided by Yokogawa Electric Corporation. This vulnerability may allow to a remote attacker to cause a denial-of-service condition to the FCN/FCJ controller by sending a crafted packet. While sending the packet, the maintenance homepage of the controller could not be accessed. Therefore, functions of the maintenance homepage, changing configuration, viewing logs, etc. are not available. But the controller’s operation is not stopped by the condition. The affected products and versions are as follows: STARDOM FCN/FCJ R1.01 to R4.31.

Additional Descriptions (1)

Se ha identificado una vulnerabilidad de consumo incontrolado de recursos en STARDOM proporcionado por Yokogawa Electric Corporation. Esta vulnerabilidad puede permitir que un atacante remoto cause una condición de denegación de servicio al controlador FCN/FCJ mediante el envío de un paquete manipulado. Mientras se enviaba el paquete, no se pudo acceder a la página de inicio de mantenimiento del controlador. Por lo tanto, las funciones de la página de inicio de mantenimiento, cambio de configuración, visualización de registros, etc. no están disponibles. Pero la condición no detiene el funcionamiento del controlador. Los productos y versiones afectados son los siguientes: STARDOM FCN/FCJ R1.01 a R4.31.

CVSS Metrics

Base Score: 5.3 (MEDIUM)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactLOW

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 1.4

Weaknesses

Source Type Description
7168b535-132a-4efe-a076-338f829b2eb9 Secondary
en CWE-400
[email protected] Primary
en NVD-CWE-noinfo

Affected Products

Vendor Product Version Update Type
yokogawa stardom_fcj_firmware * <built-in method update of dict object at 0x7e60bae0e6c0> Operating System
yokogawa stardom_fcn_firmware * <built-in method update of dict object at 0x7e60bae0d080> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:yokogawa:stardom_fcj_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:yokogawa:stardom_fcj:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:yokogawa:stardom_fcn_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:yokogawa:stardom_fcn:-:*:*:*:*:*:*:*

References

Notification
Message here