PT-2025-6205 · Siemens · Simatic S7-1200 Cpu+1
Published
2025-02-11
·
Updated
2025-02-11
·
CVE-2025-24811
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
SIMATIC S7-1200 CPU versions 6ES7211-1BE40-0XB0 through 6ES7217-1AG40-0XB0
SIPLUS S7-1200 CPU versions 6AG1212-1AE40-2XB0 through 6AG1215-1AF40-5XB0
Description:
A vulnerability has been identified in certain SIMATIC S7-1200 CPUs, where affected devices do not process correctly certain specially crafted packets sent to port 80/tcp. This could allow an unauthenticated attacker to cause a denial of service in the device.
Recommendations:
For SIMATIC S7-1200 CPU versions 6ES7211-1BE40-0XB0 through 6ES7217-1AG40-0XB0, restrict access to port 80/tcp to minimize the risk of exploitation.
For SIPLUS S7-1200 CPU versions 6AG1212-1AE40-2XB0 through 6AG1215-1AF40-5XB0, consider disabling the processing of special crafted packets on port 80/tcp until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simatic S7-1200 Cpu
Siplus S7-1200 Cpu