Denial of service is a cyber attack method that degrades or blocks the availability of a system, application, or network service by exhausting resources, which creates direct risk for enterprise uptime, transaction processing, and business continuity objectives.
As of January 10, 2023, CISA will cease updates for Siemens product vulnerabilities. Multiple vulnerabilities affecting Siemens LOGO! 8 BM Devices have been reported, allowing for potential remote code execution and device manipulation. Mitigations have been suggested while Siemens prepares fixes.
Rockwell Automation identified a vulnerability in FactoryTalk Policy Manager that may allow remote exploitation leading to Denial of Service. Versions 6.51.00 and prior are affected, with a fix available in 6.60.00 and later. Users are advised to implement security best practices.
General Industrial Controls' Lynx+ Gateway faces multiple vulnerabilities, including weak password requirements and missing authentication. These issues could lead to unauthorized access and denial of service. Users are advised to enhance security measures and follow CISA's recommendations to mitigate risks.
A vulnerability affecting Shelly Pro 4PM smart switches (versions prior to v1.6) has been reported, allowing potential Denial of Service conditions due to memory overallocation. Users are advised to update their devices and follow CISA's mitigation recommendations.
The report details a vulnerability in the Shelly Pro 3EM smart DIN rail switch, indicating a CVSS v4 score of 8.3 due to potential Denial of Service conditions. Mitigation recommendations include securing network exposure and employing firewalls and VPNs. No public exploitation has been reported.
Rockwell Automation disclosed a vulnerability in FactoryTalk Policy Manager that could lead to denial of service. The affected versions are 6.51.00 and prior, with a CVSS v4 score of 8.7. Mitigations include updating to version 6.60.00 or later and following cybersecurity best practices.
Mitsubishi Electric has reported a vulnerability in its MELSEC iQ-F Series that may allow a Denial of Service condition when exploited. Affected models are detailed, and mitigation measures are recommended.