CVE-2012-4691
Published Dec 18, 2012
Last updated 12 years ago
Overview
- Description
- Memory leak in Siemens Automation License Manager (ALM) 4.x and 5.x before 5.2 allows remote attackers to cause a denial of service (memory consumption) via crafted packets.
- Source
- ics-cert@hq.dhs.gov
- NVD status
- Analyzed
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 3.3
- Impact score
- 2.9
- Exploitability score
- 6.5
- Vector string
- AV:A/AC:L/Au:N/C:N/I:N/A:P
Weaknesses
- nvd@nist.gov
- CWE-399
Social media
- Hype score
- Not currently trending
Evaluator
- Comment
- -
- Impact
- Per: http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-783261.pdf "The attacker must have access to the local subnet where ALM is located. During installation, the default setting of the Windows firewall is to block the port used by ALM for all networks except the local subnet. If this setting has not been changed by the administrator, these vulnerabilities cannot be exploited from remote networks. Additionally, communication to this port should be blocked at network borders using appropriate security measures like firewalls."
- Solution
- Per: http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-783261.pdf "The attacker must have access to the local subnet where ALM is located. During installation, the default setting of the Windows firewall is to block the port used by ALM for all networks except the local subnet. If this setting has not been changed by the administrator, these vulnerabilities cannot be exploited from remote networks. Additionally, communication to this port should be blocked at network borders using appropriate security measures like firewalls."
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:siemens:automation_license_manager:4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C78FACDA-A891-44F8-8D7A-C1D5F4D25668" }, { "criteria": "cpe:2.3:a:siemens:automation_license_manager:5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "246E11D3-ED40-439C-B682-755516D698FB" }, { "criteria": "cpe:2.3:a:siemens:automation_license_manager:5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B0233F2E-C041-40D5-AB8F-F6C379924615" }, { "criteria": "cpe:2.3:a:siemens:automation_license_manager:5.1:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CDA04752-6735-4BBF-B5B2-801055CEB3F1" } ], "operator": "OR" } ] } ]