Vulnerabilities > CVE-2023-44322 - Unchecked Return Value vulnerability in Siemens products

047910
CVSS 5.9 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
high complexity
siemens
CWE-252

Summary

Affected devices can be configured to send emails when certain events occur on the device. When presented with an invalid response from the SMTP server, the device triggers an error that disrupts email sending. An attacker with access to the network can use this to do disable notification of users when certain events occur.

Vulnerable Configurations

Part Description Count
OS
Siemens
72
Hardware
Siemens
71

Common Weakness Enumeration (CWE)