ID

VAR-190001-0221


TITLE

Siemens SIMATIC Denial of service vulnerability

Trust: 1.6

sources: IVD: 71117ffa-1f8d-11e6-abef-000c29c66e3d // IVD: 7d7a1eb0-463f-11e9-ba2a-000c29342cb1 // CNVD: CNVD-2011-6244 // CNNVD: CNNVD-201108-081

DESCRIPTION

The Siemens SIMATIC S7-1200 CPU device is a small programmable controller from Siemens AG in Germany that meets the requirements of small and medium-sized automation systems. A denial of service vulnerability exists in Siemens SIMATIC S7-1200 and other versions. A remote attacker could exploit this vulnerability to cause the affected device to crash. The impact of this will depend on how the device is used

Trust: 1.17

sources: CNVD: CNVD-2011-6244 // BID: 48988 // IVD: 71117ffa-1f8d-11e6-abef-000c29c66e3d // IVD: 7d7a1eb0-463f-11e9-ba2a-000c29342cb1

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 1.0

sources: IVD: 71117ffa-1f8d-11e6-abef-000c29c66e3d // IVD: 7d7a1eb0-463f-11e9-ba2a-000c29342cb1 // CNVD: CNVD-2011-6244

AFFECTED PRODUCTS

vendor:siemensmodel:simatic s7-1200scope:eqversion:2.0.2

Trust: 0.6

vendor:siemensmodel:simatic s7-1200scope:ltversion:2.0.3

Trust: 0.6

vendor:siemensmodel:simatic s7-1200 siemens simatic s7-1200scope:eqversion:2.0.2<2.0.3

Trust: 0.4

sources: IVD: 71117ffa-1f8d-11e6-abef-000c29c66e3d // IVD: 7d7a1eb0-463f-11e9-ba2a-000c29342cb1 // CNVD: CNVD-2011-6244

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2011-6244
value: HIGH

Trust: 0.6

IVD: 71117ffa-1f8d-11e6-abef-000c29c66e3d
value: HIGH

Trust: 0.2

IVD: 7d7a1eb0-463f-11e9-ba2a-000c29342cb1
value: HIGH

Trust: 0.2

CNVD: CNVD-2011-6244
severity: HIGH
baseScore: 7.9
vectorString: AV:A/AC:M/AU:N/C:C/I:C/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 5.5
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: 71117ffa-1f8d-11e6-abef-000c29c66e3d
severity: HIGH
baseScore: 7.9
vectorString: AV:A/AC:M/AU:N/C:C/I:C/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 5.5
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

IVD: 7d7a1eb0-463f-11e9-ba2a-000c29342cb1
severity: HIGH
baseScore: 7.9
vectorString: AV:A/AC:M/AU:N/C:C/I:C/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 5.5
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: 71117ffa-1f8d-11e6-abef-000c29c66e3d // IVD: 7d7a1eb0-463f-11e9-ba2a-000c29342cb1 // CNVD: CNVD-2011-6244

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201108-081

TYPE

resource management error

Trust: 0.6

sources: CNNVD: CNNVD-201108-081

PATCH

title:Patch for Siemens SIMATIC Denial of Service Vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/80788

Trust: 0.6

sources: CNVD: CNVD-2011-6244

EXTERNAL IDS

db:BIDid:48988

Trust: 1.5

db:CNVDid:CNVD-2011-6244

Trust: 1.0

db:CNNVDid:CNNVD-201108-081

Trust: 0.6

db:IVDid:71117FFA-1F8D-11E6-ABEF-000C29C66E3D

Trust: 0.2

db:IVDid:7D7A1EB0-463F-11E9-BA2A-000C29342CB1

Trust: 0.2

sources: IVD: 71117ffa-1f8d-11e6-abef-000c29c66e3d // IVD: 7d7a1eb0-463f-11e9-ba2a-000c29342cb1 // CNVD: CNVD-2011-6244 // BID: 48988 // CNNVD: CNNVD-201108-081

REFERENCES

url:http://www.securityfocus.com/bid/48988

Trust: 1.2

url:http://aunz.siemens.com.au/productivity-pc-automation_simatics7-1200

Trust: 0.3

url:http://threatpost.com/en_us/blogs/black-hat-remote-dos-backdoor-easter-egg-among-newly-discovered-siemens-holes-080311

Trust: 0.3

sources: CNVD: CNVD-2011-6244 // BID: 48988 // CNNVD: CNNVD-201108-081

CREDITS

Beresford

Trust: 0.9

sources: BID: 48988 // CNNVD: CNNVD-201108-081

SOURCES

db:IVDid:71117ffa-1f8d-11e6-abef-000c29c66e3d
db:IVDid:7d7a1eb0-463f-11e9-ba2a-000c29342cb1
db:CNVDid:CNVD-2011-6244
db:BIDid:48988
db:CNNVDid:CNNVD-201108-081

LAST UPDATE DATE

2022-05-17T02:03:07.125000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2011-6244date:2016-08-26T00:00:00
db:BIDid:48988date:2011-08-03T00:00:00
db:CNNVDid:CNNVD-201108-081date:2011-08-05T00:00:00

SOURCES RELEASE DATE

db:IVDid:71117ffa-1f8d-11e6-abef-000c29c66e3ddate:2011-08-05T00:00:00
db:IVDid:7d7a1eb0-463f-11e9-ba2a-000c29342cb1date:2011-08-05T00:00:00
db:CNVDid:CNVD-2011-6244date:2011-08-05T00:00:00
db:BIDid:48988date:2011-08-03T00:00:00
db:CNNVDid:CNNVD-201108-081date:1900-01-01T00:00:00