A remote unprivileged attacker can sent multiple packages to the LMS5xx to disrupt its availability through a TCP SYN-based denial-of-service (DDoS) attack. By exploiting this vulnerability, an attacker can flood the targeted LMS5xx with a high volume of TCP SYN requests, overwhelming its resources and causing it to become unresponsive or unavailable for legitimate users.
Workaround:
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://sick.com/psirt | vendor advisory issue tracking |
https://sick.com/.well-known/csaf/white/2023/sca-2023-0007.pdf | vendor advisory |
https://sick.com/.well-known/csaf/white/2023/sca-2023-0007.json | vendor advisory |