Improper input validation in Siemens products - CVE-2018-13805

 

Improper input validation in Siemens products - CVE-2018-13805

Published: October 9, 2018 / Updated: October 10, 2018


Vulnerability identifier: #VU15304
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-13805
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The vulnerability exists due to an error when processing malicious input. A remote attacker can send a large number of specially crafted packets to the PLC and cause the PLC to lose its ability to communicate over the network.


Affected software

SIMATIC ET 200SP Open Controller
SIMATIC S7-1500 Software Controller
SIMATIC S7-1500 CPU

How to mitigate CVE-2018-13805

Update to version 2.5.

SIMATIC S7-1500 CPU - update to 2.5
SIMATIC S7-1500 Software Controller - update to 2.5

External References

Related Security Bulletins