#VU21971 Input validation error in Siemens products - CVE-2019-6575


Vulnerability identifier: #VU21971

Vulnerability risk: Medium

CVSSv4.0: 7.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/U:Green]

CVE-ID: CVE-2019-6575

CWE-ID: CWE-20

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
SIMATIC S7-1500 CPU
Hardware solutions / Firmware
SIMATIC RF600R
Server applications / SCADA systems
SIMATIC NET PC Software
Server applications / SCADA systems
SIMATIC IPC DiagMonitor
Server applications / SCADA systems
SIMATIC HMI KTP Mobile Panels
Server applications / SCADA systems
SIMATIC HMI Comfort Panels 4”-22”
Server applications / SCADA systems
SIMATIC HMI Comfort Outdoor Panels 7” & 15”
Server applications / SCADA systems
SIMATIC ET 200SP Open Controller
Server applications / SCADA systems
SIMATIC CP443-1 OPC UA
Server applications / SCADA systems
SIMATIC RF188C
Hardware solutions / Routers & switches, VoIP, GSM, etc

Vendor: Siemens

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input in the OPC UA server. A remote attacker can send a specially crafted packet on port 4840/tcp and cause a denial of service condition on the OPC communication or crash the target device.

This vulnerability affects the following products:

  • SIMATIC CP443-1 OPC UA
  • SIMATIC ET 200 Open Controller CPU 1515SPPC2
  • SIMATIC HMI Comfort Outdoor Panels 7" & 15"
  • SIMATIC HMI Comfort Panels 4" - 22":All versions
  • SIMATIC HMI KTP Mobile Panels KTP400F,KTP700, KTP700F, KTP900 and KTP900F
  • SIMATIC IPC DiagMonitor
  • SIMATIC NET PC Software
  • SIMATIC RF188C
  • SIMATIC RF600R
  • SIMATIC S7-1500 CPU family

Mitigation
Install updates from vendor's website.

Vulnerable software versions

SIMATIC S7-1500 CPU: 1.0 - 2.6

SIMATIC RF600R: before 3.2.1

SIMATIC RF188C: before 1.1.0

SIMATIC NET PC Software: 7.1

SIMATIC IPC DiagMonitor: All versions

SIMATIC HMI KTP Mobile Panels: All versions

SIMATIC HMI Comfort Panels 4”-22”: All versions

SIMATIC HMI Comfort Outdoor Panels 7” & 15”: All versions

SIMATIC ET 200SP Open Controller: before 2.7

SIMATIC CP443-1 OPC UA: All versions


External links
https://cert-portal.siemens.com/productcert/pdf/ssa-307392.pdf


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.


Latest bulletins with this vulnerability