PT-2017-19306 · Siemens · 7Km Pac Switched Ethernet Profinet Expansion Module
Published
2017-08-30
·
Updated
2017-09-12
·
CVE-2017-9945
CVSS v3.1
6.5
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Siemens 7KM PAC Switched Ethernet PROFINET expansion module versions prior to V2.1.3
Description
A Denial-of-Service condition could be induced by a specially crafted PROFINET DCP packet sent as a local Ethernet (Layer 2) broadcast. The affected component requires a manual restart via the main device to recover.
Recommendations
For versions prior to V2.1.3, update to version V2.1.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the local Ethernet (Layer 2) broadcast to minimize the risk of exploitation.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
7Km Pac Switched Ethernet Profinet Expansion Module