Denial of service in Siemens PROFINET Devices



Published: 2019-10-10 | Updated: 2019-10-18
Risk Medium
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2019-10936
CWE-ID CWE-400
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
SINAMICS DCP
Hardware solutions / Firmware

SINAMICS SM120
Hardware solutions / Firmware

SINAMICS SL150
Hardware solutions / Firmware

SINAMICS S150
Hardware solutions / Firmware

SINAMICS S120
Hardware solutions / Firmware

SINAMICS S110
Hardware solutions / Firmware

SINAMICS GM150
Hardware solutions / Firmware

SINAMICS GL150
Hardware solutions / Firmware

SINAMICS GH150
Hardware solutions / Firmware

SINAMICS G150
Hardware solutions / Firmware

SINAMICS G130
Hardware solutions / Firmware

SINAMICS G120
Hardware solutions / Firmware

SINAMICS G110M
Hardware solutions / Firmware

SINAMICS DCM
Hardware solutions / Firmware

SIMATIC WinAC RTX (F) 2010
Hardware solutions / Firmware

SIMATIC S7-400H V6
Hardware solutions / Firmware

SIMATIC S7-410 V8
Hardware solutions / Firmware

SIMATIC S7-400 V6
Hardware solutions / Firmware

SIMATIC S7-300
Hardware solutions / Firmware

SIMATIC S7-1500 CPU
Hardware solutions / Firmware

SIMATIC S7-1200
Hardware solutions / Firmware

SIMATIC PN/PN Coupler
Hardware solutions / Firmware

SIMATIC ET 200pro
Hardware solutions / Firmware

SIMATIC ET 200ecoPN
Hardware solutions / Firmware

IM 155-6 PN/3 HF
Hardware solutions / Firmware

IM 155-6 PN/2 HF
Hardware solutions / Firmware

IM 155-6 PN ST
Hardware solutions / Firmware

IM 155-6 PN HS
Hardware solutions / Firmware

IM 155-6 PN HF
Hardware solutions / Firmware

IM 155-6 PN HA
Hardware solutions / Firmware

IM 155-6 PN BA
Hardware solutions / Firmware

SIMATIC ET 200S
Hardware solutions / Firmware

IM 155-5 PN ST
Hardware solutions / Firmware

IM 155-5 PN HF
Hardware solutions / Firmware

IM 155-5 PN BA
Hardware solutions / Firmware

SIMATIC ET 200M
Hardware solutions / Firmware

SIMATIC ET 200AL
Hardware solutions / Firmware

SIMATIC CFU PA
Hardware solutions / Firmware

SINUMERIK 840D sl
Server applications / SCADA systems

SINUMERIK 828D
Server applications / SCADA systems

SIMATIC S7-400 PN/DP V7
Server applications / SCADA systems

SIMATIC HMI KTP Mobile Panels
Server applications / SCADA systems

SIMATIC HMI Comfort Panels 4”-22”
Server applications / SCADA systems

SIMATIC HMI Comfort Outdoor Panels 7” & 15”
Server applications / SCADA systems

SIMATIC PROFINET Driver
Hardware solutions / Drivers

Vendor Siemens

Security Bulletin

This security bulletin contains one medium risk vulnerability.

1) Resource exhaustion

EUVDB-ID: #VU21936

Risk: Medium

CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2019-10936

CWE-ID: CWE-400 - Resource exhaustion

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper resource management when processing UDP packets. A remote attacker can send a large amount of specially crafted UDP packets, trigger resource exhaustion and perform a denial of service (DoS) attack.

Mitigation

Install updates from vendor's website for the following products:
  • Development/Evaluation Kits for PROFINET IO:
    • DK Standard Ethernet Controller: All versions
    • EK-ERTEC 200: All versions
    • EK-ERTEC 200P: All versions
  • SIMATIC CFU PA: All versions prior to 1.2.0
  • SIMATIC ET 200AL: All versions
  • SIMATIC ET 200M: All versions
  • SIMATIC ET 200MP IM 155-5 PN BA: All versions prior to 4.2.3
  • SIMATIC ET 200MP IM 155-5 PN HF: All versions
  • SIMATIC ET 200MP IM 155-5 PN ST: All versions
  • SIMATIC ET 200S: All versions
  • SIMATIC ET 200SP IM 155-6 PN BA: All versions
  • SIMATIC ET 200SP IM 155-6 PN HA: All versions
  • SIMATIC ET 200SP IM 155-6 PN HF: All versions prior to 4.2.2
  • SIMATIC ET 200SP IM 155-6 PN HS: All versions
  • SIMATIC ET 200SP IM 155-6 PN ST: All versions
  • SIMATIC ET 200SP IM 155-6 PN/2 HF: All versions prior to 4.2.2
  • SIMATIC ET 200SP IM 155-6 PN/3 HF: All versions prior to 4.2.1
  • SIMATIC ET 200ecoPN (except 6ES7148-6JD00-0AB0 and 6ES7146-6FF00-0AB0): All versions
  • SIMATIC ET 200pro: All versions
  • SIMATIC HMI Comfort Outdoor Panels 7" & 15": All versions
  • SIMATIC HMI Comfort Panels 4" - 22": All versions
  • SIMATIC HMI KTP Mobile Panels: All versions
  • SIMATIC PN/PN Coupler: All versions
  • SIMATIC PROFINET Driver: All versions prior to 2.1
  • SIMATIC S7-1200 CPU family (incl. F): All versions
  • SIMATIC S7-1500 CPU family (incl. F): All versions prior to 2.0
  • SIMATIC S7-300 CPU family (incl. F): All versions
  • SIMATIC S7-400 PN/DP V7 (incl. F): All versions
  • SIMATIC S7-400 V6 (incl. F) and below: All versions
  • SIMATIC S7-400H V6: All versions prior to 6.0.9
  • SIMATIC S7-410 V8: All versions
  • SIMATIC WinAC RTX (F) 2010: All versions prior to SP3
  • SINAMICS DCM: All versions prior to 1.5 HF1
  • SINAMICS DCP: All versions
  • SINAMICS G110M v4.7 (PN Control Unit): All versions prior to 4.7 SP10 HF5
  • SINAMICS G120 v4.7 (PN Control Unit): All versions prior to 4.7 SP10 HF5
  • SINAMICS G130 v4.7 (Control Unit and CBE20): All versions
  • SINAMICS G150 (Control Unit and CBE20): All versions
  • SINAMICS GH150 v4.7 (Control Unit): All versions
  • SINAMICS GL150 v4.7 (Control Unit): All versions
  • SINAMICS GM150 v4.7 (Control Unit): All versions
  • SINAMICS S110 (Control Unit): All versions
  • SINAMICS S120 v4.7 (Control Unit and CBE20): All versions
  • SINAMICS S150 (Control Unit and CBE20): All versions
  • SINAMICS SL150 v4.7 (Control Unit): All versions
  • SINAMICS SM120 v4.7 (Control Unit): All versions
  • SINUMERIK 828D: All versions prior to 4.8 SP5
  • SINUMERIK 840D sl: All versions

Vulnerable software versions

SINAMICS DCP: All versions

SINUMERIK 840D sl: All versions

SINUMERIK 828D: before 4.8 SP5

SINAMICS SM120: All versions

SINAMICS SL150: All versions

SINAMICS S150: All versions

SINAMICS S120: All versions

SINAMICS S110: All versions

SINAMICS GM150: All versions

SINAMICS GL150: All versions

SINAMICS GH150: All versions

SINAMICS G150: All versions

SINAMICS G130: All versions

SINAMICS G120: before 4.7 SP10 HF5

SINAMICS G110M: before 4.7 SP10 HF5

SINAMICS DCM: before 1.5 HF1

SIMATIC WinAC RTX (F) 2010: before SP3

SIMATIC S7-400H V6: before 6.0.9

SIMATIC S7-410 V8: All versions

SIMATIC S7-400 V6: All versions

SIMATIC S7-400 PN/DP V7: All versions

SIMATIC S7-300: All versions

SIMATIC S7-1500 CPU: 1.0 - 1.8

SIMATIC S7-1200: 2.00 - 4.2.3

SIMATIC PROFINET Driver: before 2.1

SIMATIC PN/PN Coupler: All versions

SIMATIC HMI KTP Mobile Panels: All versions

SIMATIC HMI Comfort Panels 4”-22”: All versions

SIMATIC HMI Comfort Outdoor Panels 7” & 15”: All versions

SIMATIC ET 200pro: All versions

SIMATIC ET 200ecoPN: All versions

IM 155-6 PN/3 HF: before 4.2.1

IM 155-6 PN/2 HF: before 4.2.2

IM 155-6 PN ST: All versions

IM 155-6 PN HS: All versions

IM 155-6 PN HF: before 4.2.2

IM 155-6 PN HA: All versions

IM 155-6 PN BA: All versions

SIMATIC ET 200S: All versions

IM 155-5 PN ST: All versions

IM 155-5 PN HF: All versions

IM 155-5 PN BA: before 4.2.3

SIMATIC ET 200M: All versions

SIMATIC ET 200AL: All versions

SIMATIC CFU PA: 1.0.1 - 1.1.2

External links

http://cert-portal.siemens.com/productcert/pdf/ssa-473245.pdf


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###