« Volver al listado

CVE-2023-43775

Estado: ModificadaMedia (5.3)—

Denial-of-service vulnerability in the web server of the Eaton SMP Gateway allows

attacker to potentially force an unexpected restart of the automation platform, impacting the availability of the product. In rare situations, the issue could cause the SMP device to restart in Safe Mode or Max Safe Mode. When in Max Safe Mode, the product is not vulnerable anymore.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-43775",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-43775",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-09-24T13:19:33.279087Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "CybersecurityCOE@eaton.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 4.7,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "CybersecurityCOE@eaton.com",
      "affectedData": [
        {
          "vendor": "Eaton",
          "product": "SMP SG-4260",
          "versions": [
            {
              "status": "affected",
              "version": "8.0",
              "lessThan": "8.0R9",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "8.1",
              "lessThan": "8.1R5",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "8.2",
              "lessThan": "8.2R4",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Eaton",
          "product": "SMP SG-4250",
          "versions": [
            {
              "status": "affected",
              "version": "7.0"
            },
            {
              "status": "affected",
              "version": "7.1"
            },
            {
              "status": "affected",
              "version": "7.2"
            },
            {
              "status": "affected",
              "version": "8.0",
              "lessThan": "8.0R9",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "8.1",
              "lessThan": "8.1R5",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "8.2",
              "lessThan": "8.2R4",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Eaton",
          "product": "SMP 4/DP",
          "versions": [
            {
              "status": "affected",
              "version": "6.3"
            },
            {
              "status": "affected",
              "version": "7.0"
            },
            {
              "status": "affected",
              "version": "7.1"
            },
            {
              "status": "affected",
              "version": "7.2"
            },
            {
              "status": "affected",
              "version": "8.0",
              "lessThan": "8.0R9",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "8.1",
              "lessThan": "8.1R5",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "8.2",
              "lessThan": "8.2R4",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Eaton",
          "product": "SMP 16",
          "versions": [
            {
              "status": "affected",
              "version": "6.3"
            },
            {
              "status": "affected",
              "version": "7.0"
            },
            {
              "status": "affected",
              "version": "7.1"
            },
            {
              "status": "affected",
              "version": "7.2"
            },
            {
              "status": "affected",
              "version": "8.0",
              "lessThan": "8.0R9",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-09-27T15:19:34.517",
  "references": [
    {
      "url": "https://www.eaton.com/content/dam/eaton/company/news-insights/cybersecurity/security-bulletins/etn-va-2022-1008.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "CybersecurityCOE@eaton.com"
    },
    {
      "url": "https://www.eaton.com/content/dam/eaton/company/news-insights/cybersecurity/security-bulletins/etn-va-2022-1008.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "CybersecurityCOE@eaton.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-400"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Denial-of-service vulnerability in the web server of the Eaton SMP Gateway allows \n\nattacker to potentially force an unexpected restart of the automation platform, impacting the availability of the product. In rare situations, the issue could cause\nthe SMP device to restart in Safe Mode or Max Safe Mode. When in Max Safe Mode, the product is\nnot vulnerable anymore.\n"
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de denegación de servicio en el servidor web de Eaton SMP Gateway permite a un atacante forzar potencialmente un reinicio inesperado de la plataforma de automatización, lo que afecta la disponibilidad del producto. En situaciones excepcionales, el problema podría provocar que el dispositivo SMP se reinicie en Modo Seguro o Modo Seguro Máximo. Cuando está en Modo Seguro Máximo, el producto ya no es vulnerable."
    }
  ],
  "lastModified": "2026-06-17T06:26:25.147",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:eaton:smp_sg-4260_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "19285A3B-E34F-4C81-B3AF-588041DF2124",
              "versionEndExcluding": "8.0r9",
              "versionStartIncluding": "8.0"
            },
            {
              "criteria": "cpe:2.3:o:eaton:smp_sg-4260_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9561C79D-2DE3-4DCB-92DA-76A3A09ADC81",
              "versionEndExcluding": "8.1r5",
              "versionStartIncluding": "8.1"
            },
            {
              "criteria": "cpe:2.3:o:eaton:smp_sg-4260_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A7BB498B-5CFA-4525-99FA-68BAE9E8CC36",
              "versionEndExcluding": "8.2r4",
              "versionStartIncluding": "8.2"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:eaton:smp_sg-4260:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2DB90749-D036-4E69-9666-D2F12B3352AE"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:eaton:smp_sg-4250_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7E0B3C20-2670-42B6-90A7-2242225C39F6",
              "versionEndExcluding": "8.0r9",
              "versionStartIncluding": "8.0"
            },
            {
              "criteria": "cpe:2.3:o:eaton:smp_sg-4250_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "86BD7193-D822-4D96-A3D3-D2688D2CE608",
              "versionEndExcluding": "8.1r5",
              "versionStartIncluding": "8.1"
            },
            {
              "criteria": "cpe:2.3:o:eaton:smp_sg-4250_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "93609CFE-55B8-4F43-9166-D5395D6C27A2",
              "versionEndExcluding": "8.2r4",
              "versionStartIncluding": "8.2"
            },
            {
              "criteria": "cpe:2.3:o:eaton:smp_sg-4250_firmware:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "06AEBF3E-1249-45F2-9300-EEFAFAA7E38C"
            },
            {
              "criteria": "cpe:2.3:o:eaton:smp_sg-4250_firmware:7.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C6ACBFF2-A26D-451A-99FE-467EB4B5AC83"
            },
            {
              "criteria": "cpe:2.3:o:eaton:smp_sg-4250_firmware:7.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DFA92FFB-3CC4-4FEB-B6CC-F8DFE6508490"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:eaton:smp_sg-4250:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F627928D-DEE2-4028-B6FB-D67185D52CA8"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:eaton:smp_4\\/dp_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "997B78C0-A026-4145-B66C-A8F3398769CB",
              "versionEndExcluding": "8.0r9",
              "versionStartIncluding": "8.0"
            },
            {
              "criteria": "cpe:2.3:o:eaton:smp_4\\/dp_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8AB7A7BF-22BC-48C5-9897-8FFA11C06FE1",
              "versionEndExcluding": "8.1r5",
              "versionStartIncluding": "8.1"
            },
            {
              "criteria": "cpe:2.3:o:eaton:smp_4\\/dp_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0B9AF8CE-0BAF-4B3B-8138-094716BA2E97",
              "versionEndExcluding": "8.2r4",
              "versionStartIncluding": "8.2"
            },
            {
              "criteria": "cpe:2.3:o:eaton:smp_4\\/dp_firmware:6.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C0F150FA-9366-45D6-B9E8-4660F64B49EC"
            },
            {
              "criteria": "cpe:2.3:o:eaton:smp_4\\/dp_firmware:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2F9B5FAC-C4C7-4D3A-9A4C-F8017DEED7CF"
            },
            {
              "criteria": "cpe:2.3:o:eaton:smp_4\\/dp_firmware:7.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F0BBCC24-B3FB-47B7-9E81-80C8D5D6BD8C"
            },
            {
              "criteria": "cpe:2.3:o:eaton:smp_4\\/dp_firmware:7.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4A2ECEDB-E550-4774-BC21-F7CA2A24B034"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:eaton:smp_4\\/dp:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A22E3F1B-4169-48E5-A6A2-A85BFE89F005"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:eaton:smp_16_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "33F8E4EE-EBBD-4DCB-95F6-EC09BCCA1220",
              "versionEndExcluding": "8.0r9",
              "versionStartIncluding": "8.0"
            },
            {
              "criteria": "cpe:2.3:o:eaton:smp_16_firmware:6.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "99E3E73E-B44D-465B-A550-AAE11F1153BE"
            },
            {
              "criteria": "cpe:2.3:o:eaton:smp_16_firmware:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D8EE1D03-E334-4242-A738-9C6B8B95A1CF"
            },
            {
              "criteria": "cpe:2.3:o:eaton:smp_16_firmware:7.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5F97B69B-F2A6-4F6F-8E9A-3503DA56D589"
            },
            {
              "criteria": "cpe:2.3:o:eaton:smp_16_firmware:7.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A9E30826-A5F0-4946-86E9-31E878A178E3"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:eaton:smp_16:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "214D0DBE-BA0E-4C39-9361-8A845A91ED86"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "CybersecurityCOE@eaton.com"
}