ID

VAR-201106-0295


TITLE

Siemens S7-1200 WEB Service Remote Denial of Service Vulnerability

Trust: 0.2

sources: IVD: 22b3f7a0-8898-11e7-a432-000c2975a0fc

DESCRIPTION

Siemens SIMATIC S7 series PLC Used in various industrial fields, including energy, water conservancy, oil, natural gas, chemical, building automation, and manufacturing. S7-1200 During firmware update to V2.0.3 It is possible to set the controller to Stop/Detect Status, causing communication errors (for example, by running a network scan to send malformed HTTP flow). Therefore, communication errors occur at S7-1200 Web Server interface that allows the controller to enter Stop/Detect status. In automation applications, Stop/Detect A state is a state defined when an external process is stopped.

Trust: 0.2

sources: IVD: 22b3f7a0-8898-11e7-a432-000c2975a0fc

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.2

sources: IVD: 22b3f7a0-8898-11e7-a432-000c2975a0fc

AFFECTED PRODUCTS

vendor:siemensmodel: - scope:eqversion:*

Trust: 0.2

vendor:siemensmodel:simatic s7-1200 cpu;scope:eqversion:*

Trust: 0.2

sources: IVD: 22b3f7a0-8898-11e7-a432-000c2975a0fc

CVSS

SEVERITY

CVSSV2

CVSSV3

IVD: 22b3f7a0-8898-11e7-a432-000c2975a0fc
value: MEDIUM

Trust: 0.2

IVD: 22b3f7a0-8898-11e7-a432-000c2975a0fc
severity: HIGH
baseScore: 7.1
vectorString: AV:N/AC:M/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.3 [IVD]

Trust: 0.2

sources: IVD: 22b3f7a0-8898-11e7-a432-000c2975a0fc

TYPE

Denial of service

Trust: 0.2

sources: IVD: 22b3f7a0-8898-11e7-a432-000c2975a0fc

EXTERNAL IDS

db:IVDid:22B3F7A0-8898-11E7-A432-000C2975A0FC

Trust: 0.2

sources: IVD: 22b3f7a0-8898-11e7-a432-000c2975a0fc

SOURCES

db:IVDid:22b3f7a0-8898-11e7-a432-000c2975a0fc

LAST UPDATE DATE

2022-05-04T09:40:29.076000+00:00


SOURCES UPDATE DATE


SOURCES RELEASE DATE

db:IVDid:22b3f7a0-8898-11e7-a432-000c2975a0fcdate:2011-06-10T00:00:00