PT-2021-16745 · Siemens · Simatic S7-Plcsim
Published
2021-03-15
·
Updated
2021-03-18
·
CVE-2021-25674
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
SIMATIC S7-PLCSIM V5.4 (All versions)
Description
A Denial-of-Service condition can be caused in the application by an attacker with local access to the system when it is used to open a specially crafted file. This can lead to a NULL pointer deference condition, causing the application to terminate unexpectedly and requiring a restart to restore the service.
Recommendations
For SIMATIC S7-PLCSIM V5.4, avoid opening specially crafted files until a fix is available. As a temporary workaround, consider implementing access controls to limit local access to the system and prevent potential attackers from exploiting this issue.
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simatic S7-Plcsim