PT-2019-4790 · Siemens · Simatic S7-1500 Cpu

Artem Zinenko

·

Published

2019-01-08

·

Updated

2019-04-18

·

CVE-2018-16558

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions SIMATIC S7-1500 CPU versions V2.0 through V2.5 SIMATIC S7-1500 CPU versions V1.8.5 and earlier
Description A vulnerability has been identified that could allow an unauthenticated remote attacker to cause a Denial-of-Service condition of the device by sending specially crafted network packets to port 80/tcp or 443/tcp. The security vulnerability could be exploited by an attacker with network access to the affected systems on these ports. Successful exploitation requires no system privileges and no user interaction, potentially compromising the availability of the device. The issue is related to insufficient input data validation. At the time of advisory publication, no public exploitation of this security vulnerability was known.
Recommendations For SIMATIC S7-1500 CPU versions V2.0 through V2.5, update to a version V2.5 or later to resolve the issue. For SIMATIC S7-1500 CPU versions V1.8.5 and earlier, update to a version later than V1.8.5 to resolve the issue. As a temporary workaround, consider restricting access to ports 80/tcp and 443/tcp to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-01368
CVE-2018-16558

Affected Products

Simatic S7-1500 Cpu