PT-2020-2552 · Siemens · Simatic S7-1500 Software Controller+2
Published
2020-03-10
·
Updated
2020-04-02
·
CVE-2019-19281
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) versions 2.5 through 20.7
SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants) versions 2.5 through 2.7
SIMATIC S7-1500 Software Controller versions 2.5 through 20.7
Description
A vulnerability has been identified that allows an unauthenticated attacker to trigger a Denial-of-Service condition by sending specially crafted UDP packets to the device. The security vulnerability could be exploited by an attacker with network access to the affected systems, requiring no system privileges and no user interaction. This could compromise the device availability.
Recommendations
For SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) versions 2.5 through 20.7, update to version 20.8 or later.
For SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants) versions 2.5 through 2.7, update to version 2.8 or later.
For SIMATIC S7-1500 Software Controller versions 2.5 through 20.7, update to version 20.8 or later.
As a temporary workaround, consider restricting network access to the affected systems to minimize the risk of exploitation.
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simatic Et 200Sp Open Controller Cpu 1515Sp Pc2
Simatic S7-1500 Cpu
Simatic S7-1500 Software Controller