PT-2021-16746 · Siemens · Simatic S7-Plcsim
Published
2021-03-15
·
Updated
2021-03-18
·
CVE-2021-25675
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
SIMATIC S7-PLCSIM V5.4 (All versions)
Description
A Denial-of-Service condition can be caused in the application by an attacker with local access to the system when it is used to open a specially crafted file. This can lead to a divide by zero operation, causing the application to terminate unexpectedly. The service can be restored by restarting the application.
Recommendations
For SIMATIC S7-PLCSIM V5.4, avoid opening specially crafted files to prevent the Denial-of-Service condition until a fix is available. As a temporary workaround, consider implementing access controls to limit local access to the system.
Fix
Divide By Zero
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simatic S7-Plcsim