PT-2024-4088 · Siemens · Simatic S7-200 Smart Cpu Cr40+3

Published

2024-06-11

·

Updated

2024-06-11

·

CVE-2024-35292

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:P/I:N/A:C
Name of the Vulnerable Software and Affected Versions SIMATIC S7-200 SMART CPU CR40 versions All SIMATIC S7-200 SMART CPU CR60 versions All SIMATIC S7-200 SMART CPU SR20 versions All SIMATIC S7-200 SMART CPU SR30 versions All SIMATIC S7-200 SMART CPU SR40 versions All SIMATIC S7-200 SMART CPU SR60 versions All SIMATIC S7-200 SMART CPU ST20 versions All SIMATIC S7-200 SMART CPU ST30 versions All SIMATIC S7-200 SMART CPU ST40 versions All SIMATIC S7-200 SMART CPU ST60 versions All
Description A vulnerability has been identified in the SIMATIC S7-200 SMART programmable logic controller, which is related to the use of predictable IP ID sequence numbers. This makes the system susceptible to attacks that rely on predictable IP ID sequence numbers, potentially allowing an attacker to create a denial of service condition. The vulnerability can be exploited by a remote attacker to predict IP ID sequence numbers.
Recommendations For SIMATIC S7-200 SMART CPU CR40, consider implementing measures to randomize IP ID sequence numbers until a patch is available. For SIMATIC S7-200 SMART CPU CR60, consider implementing measures to randomize IP ID sequence numbers until a patch is available. For SIMATIC S7-200 SMART CPU SR20, consider implementing measures to randomize IP ID sequence numbers until a patch is available. For SIMATIC S7-200 SMART CPU SR30, consider implementing measures to randomize IP ID sequence numbers until a patch is available. For SIMATIC S7-200 SMART CPU SR40, consider implementing measures to randomize IP ID sequence numbers until a patch is available. For SIMATIC S7-200 SMART CPU SR60, consider implementing measures to randomize IP ID sequence numbers until a patch is available. For SIMATIC S7-200 SMART CPU ST20, consider implementing measures to randomize IP ID sequence numbers until a patch is available. For SIMATIC S7-200 SMART CPU ST30, consider implementing measures to randomize IP ID sequence numbers until a patch is available. For SIMATIC S7-200 SMART CPU ST40, consider implementing measures to randomize IP ID sequence numbers until a patch is available. For SIMATIC S7-200 SMART CPU ST60, consider implementing measures to randomize IP ID sequence numbers until a patch is available. As a temporary workaround, consider restricting access to the system to minimize the risk of exploitation.

Fix

Use of Insufficiently Random Values

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-04538
CVE-2024-35292

Affected Products

Simatic S7-200 Smart Cpu Cr40
Simatic S7-200 Smart Cpu Cr60
Simatic S7-200 Smart Cpu Sr20
Simatic S7-200 Smart Cpu Sr30