PT-2019-4790 · Siemens · Simatic S7-1500 Cpu
Artem Zinenko
·
Published
2019-01-08
·
Updated
2019-04-18
·
CVE-2018-16558
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
SIMATIC S7-1500 CPU versions V2.0 through V2.5
SIMATIC S7-1500 CPU versions V1.8.5 and earlier
Description
A vulnerability has been identified that could allow an unauthenticated remote attacker to cause a Denial-of-Service condition of the device by sending specially crafted network packets to port 80/tcp or 443/tcp. The security vulnerability could be exploited by an attacker with network access to the affected systems on these ports. Successful exploitation requires no system privileges and no user interaction, potentially compromising the availability of the device. The issue is related to insufficient input data validation. At the time of advisory publication, no public exploitation of this security vulnerability was known.
Recommendations
For SIMATIC S7-1500 CPU versions V2.0 through V2.5, update to a version V2.5 or later to resolve the issue.
For SIMATIC S7-1500 CPU versions V1.8.5 and earlier, update to a version later than V1.8.5 to resolve the issue.
As a temporary workaround, consider restricting access to ports 80/tcp and 443/tcp to minimize the risk of exploitation.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simatic S7-1500 Cpu