Vulnerability identifier: #VU21936
Vulnerability risk: Medium
CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID:
CWE-ID:
CWE-400
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
SINAMICS DCP
Hardware solutions /
Firmware
SINAMICS SM120
Hardware solutions /
Firmware
SINAMICS SL150
Hardware solutions /
Firmware
SINAMICS S150
Hardware solutions /
Firmware
SINAMICS S120
Hardware solutions /
Firmware
SINAMICS S110
Hardware solutions /
Firmware
SINAMICS GM150
Hardware solutions /
Firmware
SINAMICS GL150
Hardware solutions /
Firmware
SINAMICS GH150
Hardware solutions /
Firmware
SINAMICS G150
Hardware solutions /
Firmware
SINAMICS G130
Hardware solutions /
Firmware
SINAMICS G120
Hardware solutions /
Firmware
SINAMICS G110M
Hardware solutions /
Firmware
SINAMICS DCM
Hardware solutions /
Firmware
SIMATIC WinAC RTX (F) 2010
Hardware solutions /
Firmware
SIMATIC S7-400H V6
Hardware solutions /
Firmware
SIMATIC S7-410 V8
Hardware solutions /
Firmware
SIMATIC S7-400 V6
Hardware solutions /
Firmware
SIMATIC S7-300
Hardware solutions /
Firmware
SIMATIC S7-1500 CPU
Hardware solutions /
Firmware
SIMATIC S7-1200
Hardware solutions /
Firmware
SIMATIC PN/PN Coupler
Hardware solutions /
Firmware
SIMATIC ET 200pro
Hardware solutions /
Firmware
SIMATIC ET 200ecoPN
Hardware solutions /
Firmware
IM 155-6 PN/3 HF
Hardware solutions /
Firmware
IM 155-6 PN/2 HF
Hardware solutions /
Firmware
IM 155-6 PN ST
Hardware solutions /
Firmware
IM 155-6 PN HS
Hardware solutions /
Firmware
IM 155-6 PN HF
Hardware solutions /
Firmware
IM 155-6 PN HA
Hardware solutions /
Firmware
IM 155-6 PN BA
Hardware solutions /
Firmware
SIMATIC ET 200S
Hardware solutions /
Firmware
IM 155-5 PN ST
Hardware solutions /
Firmware
IM 155-5 PN HF
Hardware solutions /
Firmware
IM 155-5 PN BA
Hardware solutions /
Firmware
SIMATIC ET 200M
Hardware solutions /
Firmware
SIMATIC ET 200AL
Hardware solutions /
Firmware
SIMATIC CFU PA
Hardware solutions /
Firmware
SINUMERIK 840D sl
Server applications /
SCADA systems
SINUMERIK 828D
Server applications /
SCADA systems
SIMATIC S7-400 PN/DP V7
Server applications /
SCADA systems
SIMATIC HMI KTP Mobile Panels
Server applications /
SCADA systems
SIMATIC HMI Comfort Panels 4”-22”
Server applications /
SCADA systems
SIMATIC HMI Comfort Outdoor Panels 7” & 15”
Server applications /
SCADA systems
SIMATIC PROFINET Driver
Hardware solutions /
Drivers
Vendor: Siemens
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper resource management when processing UDP packets. A remote attacker can send a large amount of specially crafted UDP packets, trigger resource exhaustion and perform a denial of service (DoS) attack.
Mitigation
Vulnerable software versions
SINAMICS DCP: All versions
SINUMERIK 840D sl: All versions
SINUMERIK 828D: before 4.8 SP5
SINAMICS SM120: All versions
SINAMICS SL150: All versions
SINAMICS S150: All versions
SINAMICS S120: All versions
SINAMICS S110: All versions
SINAMICS GM150: All versions
SINAMICS GL150: All versions
SINAMICS GH150: All versions
SINAMICS G150: All versions
SINAMICS G130: All versions
SINAMICS G120: before 4.7 SP10 HF5
SINAMICS G110M: before 4.7 SP10 HF5
SINAMICS DCM: before 1.5 HF1
SIMATIC WinAC RTX (F) 2010: before SP3
SIMATIC S7-400H V6: before 6.0.9
SIMATIC S7-410 V8: All versions
SIMATIC S7-400 V6: All versions
SIMATIC S7-400 PN/DP V7: All versions
SIMATIC S7-300: All versions
SIMATIC S7-1500 CPU: 1.0 - 1.8
SIMATIC S7-1200: 2.00 - 4.2.3
SIMATIC PROFINET Driver: before 2.1
SIMATIC PN/PN Coupler: All versions
SIMATIC HMI KTP Mobile Panels: All versions
SIMATIC HMI Comfort Panels 4”-22”: All versions
SIMATIC HMI Comfort Outdoor Panels 7” & 15”: All versions
SIMATIC ET 200pro: All versions
SIMATIC ET 200ecoPN: All versions
IM 155-6 PN/3 HF: before 4.2.1
IM 155-6 PN/2 HF: before 4.2.2
IM 155-6 PN ST: All versions
IM 155-6 PN HS: All versions
IM 155-6 PN HF: before 4.2.2
IM 155-6 PN HA: All versions
IM 155-6 PN BA: All versions
SIMATIC ET 200S: All versions
IM 155-5 PN ST: All versions
IM 155-5 PN HF: All versions
IM 155-5 PN BA: before 4.2.3
SIMATIC ET 200M: All versions
SIMATIC ET 200AL: All versions
SIMATIC CFU PA: 1.0.1 - 1.1.2
External links
https://cert-portal.siemens.com/productcert/pdf/ssa-473245.pdf
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.