7.8
CVE-2019-18336
- EPSS 0.25%
- Veröffentlicht 10.03.2020 20:15:18
- Zuletzt bearbeitet 21.11.2024 04:33:04
- Quelle productcert@siemens.com
- Teams Watchlist Login
- Unerledigt Login
A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions < V3.X.17), SIMATIC TDC CP51M1 (All versions < V1.1.8), SIMATIC TDC CPU555 (All versions < V1.1.1), SINUMERIK 840D sl (All versions < V4.8.6), SINUMERIK 840D sl (All versions < V4.94). Specially crafted packets sent to port 102/tcp (Profinet) could cause the affected device to go into defect mode. A restart is required in order to recover the system. Successful exploitation requires an attacker to have network access to port 102/tcp, with no authentication. No user interation is required. At the time of advisory publication no public exploitation of this security vulnerability was known.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Siemens ≫ Simatic S7-300 Cpu Firmware Version < 3.3.17
Siemens ≫ Simatic S7-300 Cpu 312 Ifm Firmware Version < 3.3.17
Siemens ≫ Simatic S7-300 Cpu 313 Firmware Version < 3.3.17
Siemens ≫ Simatic S7-300 Cpu 314 Firmware Version < 3.3.17
Siemens ≫ Simatic S7-300 Cpu 314 Ifm Firmware Version < 3.3.17
Siemens ≫ Simatic S7-300 Cpu 315 Firmware Version < 3.3.17
Siemens ≫ Simatic S7-300 Cpu 315-2 Dp Firmware Version < 3.3.17
Siemens ≫ Simatic S7-300 Cpu 316-2 Dp Firmware Version < 3.3.17
Siemens ≫ Simatic S7-300 Cpu 318-2 Firmware Version < 3.3.17
Siemens ≫ Sinumerik 840d Sl Version < 4.8.6
Siemens ≫ Sinumerik 840d Sl Version < 4.94
Siemens ≫ Simatic Tdc Cp51m1 Firmware Version < 1.1.8
Siemens ≫ Simatic Tdc Cpu555 Firmware Version < 1.1.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.25% | 0.482 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
nvd@nist.gov | 7.8 | 10 | 6.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:C
|
CWE-400 Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.