CVE-2023-46219

PUBLISHED

When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware...

curl · curl

Recommended Action

Track for updates. Assess relevance to your asset inventory and enrichment workflows.

Confidence
Exploitation Status
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
CVSS / EPSS

At a Glance

When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of the HSTS status they should otherwise use.

CVE Published
Dec 12, 2023
CVSS
EPSS

Affected Versions

Vendor Product Version Status
Siemens
SIMATIC S7-1500 CPU 1518-4 PN/DP MFP

V3.1.5 to < *

Affected
Siemens
SIMATIC S7-1500 CPU 1518-4 PN/DP MFP

V3.1.5 to < *

Affected
Siemens
SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP

V3.1.5 to < *

Affected
Siemens
SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP

V3.1.5 to < *

Affected
Siemens
SIPLUS S7-1500 CPU 1518-4 PN/DP MFP

V3.1.5 to < *

Affected
Siemens
SINEC NMS

0 to < V3.0 SP1

Affected
curl
curl

8.4.0 to <= 8.4.0

Affected
curl
curl

7.84.0 to < 7.84.0

Unaffected

CVE References

Recommended Actions

  • Track for updates. Assess relevance to your asset inventory and enrichment workflows.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.