Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-18336


A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions < V3.X.17), SIMATIC TDC CP51M1 (All versions < V1.1.8), SIMATIC TDC CPU555 (All versions < V1.1.1), SINUMERIK 840D sl (All versions < V4.8.6), SINUMERIK 840D sl (All versions < V4.94). Specially crafted packets sent to port 102/tcp (Profinet) could cause the affected device to go into defect mode. A restart is required in order to recover the system. Successful exploitation requires an attacker to have network access to port 102/tcp, with no authentication. No user interation is required. At the time of advisory publication no public exploitation of this security vulnerability was known.


Published

2020-03-10T20:15:18.633

Last Modified

2024-11-21T04:33:04.367

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

6.9

Weaknesses
  • Type: Secondary
    CWE-400
  • Type: Primary
    CWE-400

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System siemens simatic_s7-300_cpu_firmware < 3.3.17 Yes
Hardware siemens simatic_s7-300_cpu - No
Operating System siemens simatic_s7-300_cpu_312_ifm_firmware < 3.3.17 Yes
Hardware siemens simatic_s7-300_cpu_312_ifm - No
Operating System siemens simatic_s7-300_cpu_313_firmware < 3.3.17 Yes
Hardware siemens simatic_s7-300_cpu_313 - No
Operating System siemens simatic_s7-300_cpu_314_firmware < 3.3.17 Yes
Hardware siemens simatic_s7-300_cpu_314 - No
Operating System siemens simatic_s7-300_cpu_314_ifm_firmware < 3.3.17 Yes
Hardware siemens simatic_s7-300_cpu_314_ifm - No
Operating System siemens simatic_s7-300_cpu_315_firmware < 3.3.17 Yes
Hardware siemens simatic_s7-300_cpu_315 - No
Operating System siemens simatic_s7-300_cpu_315-2_dp_firmware < 3.3.17 Yes
Hardware siemens simatic_s7-300_cpu_315-2_dp - No
Operating System siemens simatic_s7-300_cpu_316-2_dp_firmware < 3.3.17 Yes
Hardware siemens simatic_s7-300_cpu_316-2_dp - No
Operating System siemens simatic_s7-300_cpu_318-2_firmware < 3.3.17 Yes
Hardware siemens simatic_s7-300_cpu_318-2 - No
Application siemens sinumerik_840d_sl < 4.8.6 Yes
Application siemens sinumerik_840d_sl < 4.94 Yes
Operating System siemens simatic_tdc_cp51m1_firmware < 1.1.8 Yes
Hardware siemens simatic_tdc_cp51m1 - No
Operating System siemens simatic_tdc_cpu555_firmware < 1.1.1 Yes
Hardware siemens simatic_tdc_cpu555 - No

References