ID

VAR-201106-0303


TITLE

Siemens S7-1200 Communication Protocol Replay Vulnerability

Trust: 0.2

sources: IVD: b4d90936-8898-11e7-a432-000c2975a0fc

DESCRIPTION

Siemens SIMATIC S7 series PLC Used in various industrial fields, including energy, water conservancy, oil, natural gas, chemical, building automation, and manufacturing. S7-1200 Trigger CPU functions During firmware update to V2.0.3 It is possible to replay the communication process between the engineering software and the controller through an open source tool later. This results in that the engineering software can issue commands to the controller at a later time (for example, setting the control) regardless of whether the controller has a password configuration. Device stopped working)

Trust: 0.2

sources: IVD: b4d90936-8898-11e7-a432-000c2975a0fc

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.2

sources: IVD: b4d90936-8898-11e7-a432-000c2975a0fc

AFFECTED PRODUCTS

vendor:siemensmodel: - scope:eqversion:*

Trust: 0.2

vendor:siemensmodel:simatic s7-1200 cpu;scope:eqversion:*

Trust: 0.2

sources: IVD: b4d90936-8898-11e7-a432-000c2975a0fc

CVSS

SEVERITY

CVSSV2

CVSSV3

IVD: b4d90936-8898-11e7-a432-000c2975a0fc
value: HIGH

Trust: 0.2

IVD: b4d90936-8898-11e7-a432-000c2975a0fc
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.3 [IVD]

Trust: 0.2

sources: IVD: b4d90936-8898-11e7-a432-000c2975a0fc

TYPE

Denial of service

Trust: 0.2

sources: IVD: b4d90936-8898-11e7-a432-000c2975a0fc

EXTERNAL IDS

db:IVDid:B4D90936-8898-11E7-A432-000C2975A0FC

Trust: 0.2

sources: IVD: b4d90936-8898-11e7-a432-000c2975a0fc

SOURCES

db:IVDid:b4d90936-8898-11e7-a432-000c2975a0fc

LAST UPDATE DATE

2022-05-04T10:09:26.045000+00:00


SOURCES UPDATE DATE


SOURCES RELEASE DATE

db:IVDid:b4d90936-8898-11e7-a432-000c2975a0fcdate:2011-06-10T00:00:00