Siemens Automation License Manager (ALM) before 5.3 SP3 Update 1 allows remote attackers to cause a denial of service (ALM service outage) via crafted packets to TCP port 4410.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-16-287-02 | |
http://www.securitytracker.com/id/1037011 | vdb entry |
http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-284342.pdf | patch vendor advisory |
http://www.securityfocus.com/bid/93553 | vdb entry third party advisory |