PT-2018-2567 · Siemens · Simatic S7-400 Cpu 416-3 Dp+13

Published

2018-11-13

·

Updated

2023-05-09

·

CVE-2018-16557

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:N/I:P/A:C
Name of the Vulnerable Software and Affected Versions SIMATIC S7-400 CPU 412-1 DP V7 versions prior to V7.0.3 SIMATIC S7-400 CPU 412-2 DP V7 versions prior to V7.0.3 SIMATIC S7-400 CPU 412-2 PN V7 versions prior to V7.0.3 SIMATIC S7-400 CPU 414-2 DP V7 versions prior to V7.0.3 SIMATIC S7-400 CPU 414-3 DP V7 versions prior to V7.0.3 SIMATIC S7-400 CPU 414-3 PN/DP V7 versions prior to V7.0.3 SIMATIC S7-400 CPU 414F-3 PN/DP V7 versions prior to V7.0.3 SIMATIC S7-400 CPU 416-2 DP V7 versions prior to V7.0.3 SIMATIC S7-400 CPU 416-3 DP V7 versions prior to V7.0.3 SIMATIC S7-400 CPU 416-3 PN/DP V7 versions prior to V7.0.3 SIMATIC S7-400 CPU 416F-2 DP V7 versions prior to V7.0.3 SIMATIC S7-400 CPU 416F-3 PN/DP V7 versions prior to V7.0.3 SIMATIC S7-400 CPU 417-4 DP V7 versions prior to V7.0.3 SIMATIC S7-400 H V4.5 and below CPU family versions prior to V4.5 SIMATIC S7-400 H V6 CPU family versions prior to V6.0.9 SIMATIC S7-400 PN/DP V6 and below CPU family versions prior to V6 SIMATIC S7-410 CPU family versions prior to V8.2.1 SIPLUS S7-400 CPU 414-3 PN/DP V7 versions prior to V7.0.3 SIPLUS S7-400 CPU 416-3 PN/DP V7 versions prior to V7.0.3 SIPLUS S7-400 CPU 416-3 V7 versions prior to V7.0.3 SIPLUS S7-400 CPU 417-4 V7 versions prior to V7.0.3
Description The issue is related to errors in input validation by the Ethernet, PROFIBUS, and MPI interfaces, which could allow a remote attacker to cause a denial of service condition by sending specially crafted packets to port 102/tcp. Successful exploitation requires network access to the device and no user interaction is required. If no access protection is configured, no privileges are required to exploit the security vulnerability. The vulnerability could compromise the availability of the system.
Recommendations For SIMATIC S7-400 CPU 412-1 DP V7 versions prior to V7.0.3, flashing with a firmware image may be required to recover the CPU. For SIMATIC S7-400 CPU 412-2 DP V7 versions prior to V7.0.3, flashing with a firmware image may be required to recover the CPU. For SIMATIC S7-400 CPU 412-2 PN V7 versions prior to V7.0.3, flashing with a firmware image may be required to recover the CPU. For SIMATIC S7-400 CPU 414-2 DP V7 versions prior to V7.0.3, flashing with a firmware image may be required to recover the CPU. For SIMATIC S7-400 CPU 414-3 DP V7 versions prior to V7.0.3, flashing with a firmware image may be required to recover the CPU. For SIMATIC S7-400 CPU 414-3 PN/DP V7 versions prior to V7.0.3, flashing with a firmware image may be required to recover the CPU. For SIMATIC S7-400 CPU 414F-3 PN/DP V7 versions prior to V7.0.3, flashing with a firmware image may be required to recover the CPU. For SIMATIC S7-400 CPU 416-2 DP V7 versions prior to V7.0.3, flashing with a firmware image may be required to recover the CPU. For SIMATIC S7-400 CPU 416-3 DP V7 versions prior to V7.0.3, flashing with a firmware image may be required to recover the CPU. For SIMATIC S7-400 CPU 416-3 PN/DP V7 versions prior to V7.0.3, flashing with a firmware image may be required to recover the CPU. For SIMATIC S7-400 CPU 416F-2 DP V7 versions prior to V7.0.3, flashing with a firmware image may be required to recover the CPU. For SIMATIC S7-400 CPU 416F-3 PN/DP V7 versions prior to V7.0.3, flashing with a firmware image may be required to recover the CPU. For SIMATIC S7-400 CPU 417-4 DP V7 versions prior to V7.0.3, flashing with a firmware image may be required to recover the CPU. For SIMATIC S7-400 H V4.5 and below CPU family versions prior to V4.5, flashing with a firmware image may be required to recover the CPU. For SIMATIC S7-400 H V6 CPU family versions prior to V6.0.9, flashing with a firmware image may be required to recover the CPU. For SIMATIC S7-400 PN/DP V6 and below CPU family versions prior to V6, flashing with a firmware image may be required to recover the CPU. For SIMATIC S7-410 CPU family versions prior to V8.2.1, flashing with a firmware image may be required to recover the CPU. For SIPLUS S7-400 CPU 414-3 PN/DP V7 versions prior to V7.0.3, flashing with a firmware image may be required to recover the CPU. For SIPLUS S7-400 CPU 416-3 PN/DP V7 versions prior to V7.0.3, flashing with a firmware image may be required to recover the CPU. For SIPLUS S7-400 CPU 416-3 V7 versions prior to V7.0.3, flashing with a firmware image may be required to recover the CPU. For SIPLUS S7-400 CPU 417-4 V7 versions prior to V7.0.3, flashing with a firmware image may be required to recover the CPU. As a temporary workaround, consider restricting access to port 102/tcp via Ethernet interface or to the PROFIBUS or Multi Point Interfaces (MPI) to minimize the risk of exploitation.

Fix

RCE

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

BDU:2019-01022
CVE-2018-16557

Affected Products

Simatic S7-400 Cpu 412-1 Dp
Simatic S7-400 Cpu 412-2 Dp
Simatic S7-400 Cpu 414-2 Dp
Simatic S7-400 Cpu 414-3 Dp
Simatic S7-400 Cpu 416-2 Dp
Simatic S7-400 Cpu 416-3 Dp
Simatic S7-400 Cpu 417-4 Dp
Simatic S7-400 H
Simatic S7-400 Pn Cpu
Simatic S7-410
Siplus S7-400 Cpu 414-3 Pn/Dp
Siplus S7-400 Cpu 416-3
Siplus S7-400 Cpu 416-3 Pn/Dp
Siplus S7-400 Cpu 417-4