PT-2021-20312 · Siemens · Siplus Net Cp 443-1 Advanced+6

Published

2021-09-14

·

Updated

2023-04-11

·

CVE-2021-33737

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: SIMATIC CP 343-1 (incl. SIPLUS variants) (All versions) SIMATIC CP 343-1 Advanced (incl. SIPLUS variants) (All versions) SIMATIC CP 343-1 ERPC (All versions) SIMATIC CP 343-1 Lean (incl. SIPLUS variants) (All versions) SIMATIC CP 443-1 versions prior to V3.3 SIMATIC CP 443-1 Advanced versions prior to V3.3 SIPLUS NET CP 443-1 versions prior to V3.3 SIPLUS NET CP 443-1 Advanced versions prior to V3.3
Description: A vulnerability has been identified that could cause a denial of service condition when a specially crafted packet is sent to port 102/tcp of an affected device. This results in the need for a restart to restore normal operations.
Recommendations: For SIMATIC CP 343-1 (incl. SIPLUS variants), consider restricting access to port 102/tcp until a fix is available. For SIMATIC CP 343-1 Advanced (incl. SIPLUS variants), consider restricting access to port 102/tcp until a fix is available. For SIMATIC CP 343-1 ERPC, consider restricting access to port 102/tcp until a fix is available. For SIMATIC CP 343-1 Lean (incl. SIPLUS variants), consider restricting access to port 102/tcp until a fix is available. For SIMATIC CP 443-1 versions prior to V3.3, update to version V3.3 or later. For SIMATIC CP 443-1 Advanced versions prior to V3.3, update to version V3.3 or later. For SIPLUS NET CP 443-1 versions prior to V3.3, update to version V3.3 or later. For SIPLUS NET CP 443-1 Advanced versions prior to V3.3, update to version V3.3 or later.

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2021-33737

Affected Products

Simatic Cp 343-1
Simatic Cp 343-1 Advanced
Simatic Cp 343-1 Erpc
Simatic Cp 343-1 Lean
Simatic Cp 443-1
Siplus Net Cp 443-1
Siplus Net Cp 443-1 Advanced