Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2019-13925

A vulnerability has been identified in SCALANCE S602 (All versions >= V3.0 and < V4.1), SCALANCE S612 (All versions >= V3.0 and < V4.1), SCALANCE S623 (All versions >= V3.0 and < V4.1), SCALANCE S627-2M (All versions >= V3.0 and < V4.1). Specially crafted packets sent to port 443/tcp of affected devices could cause a Denial-of-Service condition of the web server.

CVE
#vulnerability#web#dos#js#pdf

%PDF-1.5 %���� 1 0 obj << /D [2 0 R /XYZ 70.866 771.024 null] >> endobj 3 0 obj << /D [2 0 R /XYZ 70.866 646.963 null] >> endobj 4 0 obj << /D [5 0 R /XYZ 70.866 623.379 null] >> endobj 6 0 obj << /D [5 0 R /XYZ 70.866 542.368 null] >> endobj 7 0 obj << /D [8 0 R /XYZ 85.039 451.373 null] >> endobj 9 0 obj << /D [8 0 R /XYZ 70.866 184.038 null] >> endobj 10 0 obj << /S /GoTo /D [2 0 R /Fit] >> endobj 2 0 obj << /Contents 11 0 R /Type /Page /Resources 12 0 R /Parent 13 0 R /Annots [14 0 R 15 0 R 16 0 R 17 0 R 18 0 R 19 0 R] /MediaBox [0 0 595.276 841.89] >> endobj 14 0 obj << /A << /S /URI /Type /Action /URI (https://support.industry.siemens.com/cs/document/109756957) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [450.608 427.635 518.276 439.052] >> endobj 16 0 obj << /A << /S /URI /Type /Action /URI (https://support.industry.siemens.com/cs/document/109756957) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [450.608 301.909 518.276 313.326] >> endobj 18 0 obj << /A << /S /URI /Type /Action /URI (https://support.industry.siemens.com/cs/document/109756957) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [450.608 176.182 518.276 187.599] >> endobj 20 0 obj << /A << /S /URI /Type /Action /URI (https://support.industry.siemens.com/cs/document/109756957) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [450.608 684.645 518.276 696.062] >> endobj 12 0 obj << /ProcSet [/PDF /Text] /Font << /F49 21 0 R /F46 22 0 R >> >> endobj 11 0 obj << /Filter /FlateDecode /Length 1993 >> stream x��Z�n�F}�W����/A[�q��En��E���m"������}g/�D�V%ȱ�\qggfϞ9# G7��8y>>9}�ed��TF��Ha����1H�’��x�g�l^ �T�x���r0$"���~�lr�W 2��/��oMW�eZ�_\����������ɿ’�Y; �b$Jg’?�h��aČ���7g ��~�N�>�!��ڲi�SB"��.��#��ʤϏ�C�+�� a�:$ht6�p,�mD�@�@���ڛ`���5�3��"1"B��0`"ξ�8�5Ҋ��4GL�>� EJ�}LȾ�;�cƐ������<+�/�4��ڎ�j��0�DB A��#B!mfW$�S ��m����}�3�’{��RȈ��[cR�� 8?{u�����}8R�У�*���1� ��6c�q(1���S�$����Dj�������a�M�쾴T����8�� �˄�2�O��g��y�t�=�Ӥ΋���I�=bל�S<�tH�] ��E�鯒��s�?K(B�,2�|HXk��Ηe������㬬`u�͉&�{�h�����t��wϓ* ’-J뀒"VH�� ɡ�����jL�b�E��� E�󀧫ׯ�.����;���z��H�XMa#f0y|k� :��1��JE<�f77)��Fb[p������ H^�e���?O2;p��Y��b^’�<<��[�i�/�aX۪� �9��#k��������k$nqqD�� / � bsZ,�0�e�L�����>�8���2�u^��$�`�: �G��_!,+1�Ël�’�aq=e^��t�T~�"XZd嵕’EȾ=/����ƋQtТ��7>�N�XB�ۺ��K��u v��3!+k��6 7e6����t�-|�<�nO�&�v�YZ7�^��Y�|�XN��8 ،��h�y���S�|���.�]���eE@��T���pd�Y�.7ch���a�/�2 W�� ��� W�vsH:e{s� � ��|yq>�xѣ�����ge(��b�lb���8���yk�����.-߾�:�z"0 1}\F�� ������T��ozrO)(ܣ��9w��B�]�[c\��㣷����}ӃY˔40Km�cd�������@6�����e^�`C6]5�����:#��� �&1���qJm�D�e]o�wM�7�V�<�@���3 =[���������|�a��e,O]ۘ2 ,�����F��Ȅ0 Z��vF.��Lr/�tXt�6�`q��#mt�2�Q�?���l^� ,n@�a�iu�Ԕ���#��������8oP�V�g�i��uӍ��[�&C���_�’��-�� ؇�B��V�M�Q��6��j��nG]�o&s����bn�*g�s�9���8ɧ��J��wy��YI#;:Z.N���n)���d���ٛ��:�)�>o��.5(�r��v�&�^7� ��Q&��벘ݻ&�Eշ���F�^�n�H�����’,p���fQ�n,�>Ʒu�����V�A�Dt]�C�TЪ9(誶��@Kit���o�\A$����H�0V�l��5B��f�����X��öP,N �P<^$uzk���v���p?8��B?����rU�z���n�`��� Q���H{�u���*�%�1�����_��XzѬ���� �~ ��MX�^.>��n�(�Sg�c��X���~U ���IxK�~.&?5?DVh�Lá\�]���\̸���^\�4�B=*3��`� ��Bz4.� }b.��8��\Lmۦ�\|����Qkyk��P�w{.�� �U?S�3s�Cda���4���;�$\L �����������b �*�\L��>ۿ3)��� g��ŏeb��B�ć��-�&�:�D{S�fP��!?S��7�~����%�0M��=����� e�`?� ��.���w9�?V��l endstream endobj 23 0 obj << /D [2 0 R /XYZ 69.866 808.885 null] >> endobj 22 0 obj << /Subtype /Type1 /FirstChar 2 /Type /Font /BaseFont /FJXJHV+NimbusSanL-Regu /FontDescriptor 24 0 R /Encoding 25 0 R /LastChar 184 /Widths 26 0 R >> endobj 21 0 obj << /Subtype /Type1 /FirstChar 45 /Type /Font /BaseFont /LBLQAF+NimbusSanL-Bold /FontDescriptor 27 0 R /Encoding 25 0 R /LastChar 121 /Widths 28 0 R >> endobj 29 0 obj << /D [2 0 R /XYZ 70.866 524.28 null] >> endobj 15 0 obj << /A << /S /URI /Type /Action /URI (https://support.industry.siemens.com/cs/document/109756957) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 415.68 515.583 427.097] >> endobj 17 0 obj << /A << /S /URI /Type /Action /URI (https://support.industry.siemens.com/cs/document/109756957) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 289.953 515.583 301.37] >> endobj 19 0 obj << /A << /S /URI /Type /Action /URI (https://support.industry.siemens.com/cs/document/109756957) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 164.227 515.583 175.644] >> endobj 13 0 obj << /Kids [2 0 R 5 0 R 8 0 R 30 0 R] /Type /Pages /Count 4 >> endobj 31 0 obj << /A << /S /URI /Type /Action /URI (https://www.siemens.com/cert/operational-guidelines-industrial-security) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [164.798 448.314 487.754 459.85] >> endobj 32 0 obj << /A << /S /URI /Type /Action /URI (https://www.siemens.com/industrialsecurity) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [406.699 418.545 525.406 429.962] >> endobj 33 0 obj << /A << /S /URI /Type /Action /URI (https://www.first.org/cvss/) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [131.954 218.58 248.203 230.117] >> endobj 34 0 obj << /A << /S /URI /Type /Action /URI (https://cwe.mitre.org/) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [69.87 128.917 163.926 140.453] >> endobj 35 0 obj << /A << /S /URI /Type /Action /URI (https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N/E:P/RL:O/RC:C) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [224.029 660.156 507.302 674.104] >> endobj 36 0 obj << /ProcSet [/PDF /Text] /Font << /F49 21 0 R /F46 22 0 R >> >> endobj 5 0 obj << /Contents 37 0 R /Type /Page /Resources 36 0 R /Parent 13 0 R /Annots [20 0 R 38 0 R 31 0 R 32 0 R 39 0 R 33 0 R 34 0 R] /MediaBox [0 0 595.276 841.89] >> endobj 37 0 obj << /Filter /FlateDecode /Length 2837 >> stream xڭZ�s�H�o��b�<���Uio�{y��d�j���2 ������3�ú���hhfz�{�������B���ϋ��_��� �\{�/ �Xk/J�@��[d�����7y�L�y��|��’�L�E��H��h* �з�oލ�?�U�[���� �^L�X�zu����@���� �[n�~�#�2x��"��g3s�I%%�����_W�U�Nj!�^�Y�T2�$z�� ���P��B�P�> ��%�l91md�G2�Jk��������ZJ�蚿m��s����{�]�1x�]3$J��zM��&\�y����?�N�_D�(-3�;�����“(�"��B��X``���,ms���"yx�V�n�P�P��b)�_4�[��8R~��&�~Z�S�k;��HiN�H��[�ω����͹t(i�eU��=%��P҉p��&,�k�/�P��i�=O ���R����˼1�%u�o)x��C]mN�Gp1�����Ϯu.������O7 ���*�.�������w��m��뛛�g��I��X�8�je�kZX���$�4�ޠu��67��&��;��7,L"� �؀|’�Ak�ܪl|[E�O�[TNE�ߦ��1o�����D>� ֫ɵ����� c�j���ݳ��>K�XGV�:�@#�M�qH�fFM�D:=�6��ܿ�u�+3�u9�Z@Da�ƭ�m����T�A���c� �j��X��9��ua�YD��Ǣ�\yH€ ٱ�4�x vRqҫu:�L ʤ���>��szo�?����0W�@�P �� �U��p����L�h���Û#�C^��K��]�%���Y 5������t�6�����~T=0و!XP�kj���pCAj��"��R| C�gDis< �Ȗ�sQ���l�Y���g��&Be?B፭������4ZB��6P��cZڵ����j�N��"b.�@�wE��,k���K�)!�p3��ʹ�ڧR�\�JIXh3��҉��R�c����>L�O) Z�tuVn�]���ܢ�^��jJ�M^ӛYvG��N#<0�;�>����T���V��գ4�e� ���`Js����hM ��S�C�Iu������/�?*��8������wGB�@� v>�< ��Hv���YّP��og����>�wx��E���2�&arV|��H9���v����[H���^�A|�JD���*N�5,la~Vy�������JR��M�6���{m�Y��U�Z����o1>��a�#>L�e�>O�.cY�l�W ��T`�:4�� A;sRX��\��.�W]m�&�KPe��Btm��&`�;a��(֥�j�[kb \hK� @If�PA�f~���k�� 2@;�t� ��+�:{�� B 5T�|� �$)��ǂ�ƒ��ތ�$"ԥ���-+�O����:W;�W�ds+�Ϛ��Ƭ+N(��q�G6n�a��ʾ�J��’���������D%G�{n;���B�Э$=���@�f ��’���5�’*&�@���+�X�G����(G��� 6P�A�]�n� q,p���N�YV��ء���p��G���~�Gl��CD��f1��|!,�03r�%;��r���g�[j��y5|��A�G*�>�c�UD�_,�R� ʫ��3�>��y�8^bU]�����^����Ƒj��v>�������¤@0�r��G�����4�� ��L�sr�J2��P-���V��j.�Lnؘ� \.#�)7@�)$#����<���9� ��t�C�����R���]���jF�Q�l�C�R����9�40��$ ��

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda