CVE-2024-44087
https://notcve.org/view.php?id=CVE-2024-44087
This could allow an unauthenticated remote attacker to cause an integer overflow and crash of the application. This denial of service condition could prevent legitimate users from using subsequent products that rely on the affected application for license verification. • https://cert-portal.siemens.com/productcert/html/ssa-103653.html • CWE-190: Integer Overflow or Wraparound •
CVE-2024-43647
https://notcve.org/view.php?id=CVE-2024-43647
This could allow an unauthenticated remote attacker to cause a denial of service condition. To restore normal operations, the network cable of the device needs to be unplugged and re-plugged. • https://cert-portal.siemens.com/productcert/html/ssa-969738.html • CWE-400: Uncontrolled Resource Consumption •
CVE-2024-37993
https://notcve.org/view.php?id=CVE-2024-37993
The affected applications do not authenticated the creation of Ajax2App instances. This could allow an unauthenticated attacker to cause a denial of service condition. • https://cert-portal.siemens.com/productcert/html/ssa-765405.html • CWE-284: Improper Access Control •
CVE-2023-30756
https://notcve.org/view.php?id=CVE-2023-30756
The web server of the affected devices do not properly handle certain errors when using the Expect HTTP request header, resulting in NULL dereference. This could allow a remote attacker with no privileges to cause a denial of service condition in the system. • https://cert-portal.siemens.com/productcert/html/ssa-423808.html • CWE-476: NULL Pointer Dereference •
CVE-2023-30755
https://notcve.org/view.php?id=CVE-2023-30755
The web server of the affected devices do not properly handle the shutdown or reboot request, which could lead to the clean up of certain resources. This could allow a remote attacker with elevated privileges to cause a denial of service condition in the system. • https://cert-portal.siemens.com/productcert/html/ssa-423808.html • CWE-476: NULL Pointer Dereference •