Denial of service in Siemens SIMATIC S7-400 CPUs

Published: 2018-05-16 12:59:47
Severity Low
Patch available YES
Number of vulnerabilities 1
CVE ID CVE-2018-4850
CVSSv3 6.7 [CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C]
CWE ID CWE-20
Exploitation vector Network
Public exploit Public exploit code for vulnerability #1 is available.
Vulnerable software SIMATIC S7-400 H
SIMATIC S7-400
Vulnerable software versions SIMATIC S7-400 H 4.5
SIMATIC S7-400 H -
SIMATIC S7-400 5.2
SIMATIC S7-400 5.1
SIMATIC S7-400 5.0
SIMATIC S7-400 4.0
Vendor URL Siemens

Security Advisory

1) Improper input validation

Description

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to improper validation of S7 communication packets. A remote attacker can send a specially crafted S7 communication packet to a communication interface of the CPU and cause the core functionality of the CPU to crash.

Remediation

Install update from vendor's website.

External links

https://cert-portal.siemens.com/productcert/pdf/ssa-914382.pdf

Back to List