Denial of service in Siemens SIMATIC S7-1500 and SIMATIC ET 200SP Open Controller

Published: 2018-10-10 19:21:45
Severity Low
Patch available YES
Number of vulnerabilities 1
CVE ID CVE-2018-13805
CVSSv3 4.6 [CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]
CWE ID CWE-20
Exploitation vector Network
Public exploit Not available
Vulnerable software SIMATIC ET 200SP Open Controller
SIMATIC S7-1500
SIMATIC S7-1500 Software Controller
Vulnerable software versions SIMATIC ET 200SP Open Controller -
SIMATIC S7-1500 -
SIMATIC S7-1500 Software Controller -
Vendor URL Siemens

Security Advisory

1) Improper input validation

Description

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The vulnerability exists due to an error when processing malicious input. A remote attacker can send a large number of specially crafted packets to the PLC and cause the PLC to lose its ability to communicate over the network.

Remediation

Update to version 2.5.

External links

https://cert-portal.siemens.com/productcert/pdf/ssa-347726.pdf

Back to List