CVE-2023-43775
Last modified
CVE-2023-43775 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Denial-of-service vulnerability in the web server of the Eaton SMP Gateway allows attacker to potentially force an unexpected restart of the automation platform, impacting the availability of the product. In rare situations, the issue could cause the SMP device to restart in Safe Mode or Max Safe Mode. EPSS estimates a 0.67% chance of exploitation in the next 30 days.
Description
Denial-of-service vulnerability in the web server of the Eaton SMP Gateway allows attacker to potentially force an unexpected restart of the automation platform, impacting the availability of the product. In rare situations, the issue could cause the SMP device to restart in Safe Mode or Max Safe Mode. When in Max Safe Mode, the product is not vulnerable anymore.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Eaton | Smp Sg-4260 Firmware | >= 8.0, < 8.0r9 |
| Eaton | Smp Sg-4260 Firmware | >= 8.1, < 8.1r5 |
| Eaton | Smp Sg-4260 Firmware | >= 8.2, < 8.2r4 |
| Eaton | Smp Sg-4250 Firmware | >= 8.0, < 8.0r9 |
| Eaton | Smp Sg-4250 Firmware | >= 8.1, < 8.1r5 |
| Eaton | Smp Sg-4250 Firmware | >= 8.2, < 8.2r4 |
| Eaton | Smp Sg-4250 Firmware | 7.0 |
| Eaton | Smp Sg-4250 Firmware | 7.1 |
| Eaton | Smp Sg-4250 Firmware | 7.2 |
| Eaton | Smp 4\/Dp Firmware | >= 8.0, < 8.0r9 |
| Eaton | Smp 4\/Dp Firmware | >= 8.1, < 8.1r5 |
| Eaton | Smp 4\/Dp Firmware | >= 8.2, < 8.2r4 |
| Eaton | Smp 4\/Dp Firmware | 6.3 |
| Eaton | Smp 4\/Dp Firmware | 7.0 |
| Eaton | Smp 4\/Dp Firmware | 7.1 |
| Eaton | Smp 4\/Dp Firmware | 7.2 |
| Eaton | Smp 16 Firmware | >= 8.0, < 8.0r9 |
| Eaton | Smp 16 Firmware | 6.3 |
| Eaton | Smp 16 Firmware | 7.0 |
| Eaton | Smp 16 Firmware | 7.1 |
| Eaton | Smp 16 Firmware | 7.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-43775?
How severe is CVE-2023-43775?
How do I fix CVE-2023-43775?
Are you affected by CVE-2023-43775?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
