Release date:
Updated on:
Affected Systems:
Siemens simatic hmi 4.0-5.2
Description:
--------------------------------------------------------------------------------
Bugtraq id: 56954
CVE (CAN) ID: CVE-2012-4691
Siemens Automation License Manager is a system that processes remote and Local Certificates for HMI, SCADA, and industrial products.
Automation License Manager 4.0-5.2 has the memory leakage vulnerability. attackers can send specially crafted packets to port 4410/TCP, which can cause memory leakage and resource consumption, leading to dos.
<* Source: CERT
Link: http://www.us-cert.gov/control_systems/pdf/ICSA-12-349-01.pdf
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Siemens
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.siemens.com/corporate-technology/pool/