CVE-2023-35920: Siemens SIMATIC MV540 H Firmware

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3.4), SIMATIC MV540 S (All versions < V3.3.4), SIMATIC MV550 H (All versions < V3.3.4), SIMATIC MV550 S (All versions < V3.3.4), SIMATIC MV560 U (All versions < V3.3.4), SIMATIC MV560 X (All versions < V3.3.4). Affected devices cannot properly process specially crafted IP packets sent to the devices. This could allow an unauthenticated remote attacker to cause a denial of service condition. The affected devices must be restarted manually.

Affected products

  • Siemens SIMATIC MV540 H Firmware: before 3.3.4 (fixed in 3.3.4)
  • Siemens SIMATIC MV540 S Firmware: before 3.3.4 (fixed in 3.3.4)
  • Siemens SIMATIC MV550 H Firmware: before 3.3.4 (fixed in 3.3.4)
  • Siemens SIMATIC MV550 S Firmware: before 3.3.4 (fixed in 3.3.4)
  • Siemens SIMATIC MV560 U Firmware: before 3.3.4 (fixed in 3.3.4)
  • Siemens SIMATIC MV560 X Firmware: before 3.3.4 (fixed in 3.3.4)

Published 2023-07-11. Last modified 2026-06-17.