ID

VAR-201106-0304


TITLE

Siemens SIMATIC PLC Memory read and write vulnerabilities

Trust: 0.2

sources: IVD: ce438fd6-8898-11e7-a432-000c2975a0fc

DESCRIPTION

Siemens SIMATIC S7 series PLC Used in various industrial fields, including energy, water conservancy, oil, natural gas, chemical, building automation, and manufacturing. Read and write users PLC Memory capacity is based on Siemens ISO-TSAP An integral part of the open architecture of the protocol allows Siemens and non-Siemens products to access programmable controller memory, input and output constants and variables. As a result, devices implementing the protocol have proven to be vulnerable.

Trust: 0.2

sources: IVD: ce438fd6-8898-11e7-a432-000c2975a0fc

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.2

sources: IVD: ce438fd6-8898-11e7-a432-000c2975a0fc

AFFECTED PRODUCTS

vendor:siemensmodel: - scope:eqversion:*

Trust: 0.8

vendor:siemensmodel:simatic s7-300;scope:eqversion:*

Trust: 0.2

vendor:siemensmodel:simatic s7-1200;scope:eqversion:*

Trust: 0.2

vendor:siemensmodel:simatic s7-200;scope:eqversion:*

Trust: 0.2

vendor:siemensmodel:simatic s7-400;scope:eqversion:*

Trust: 0.2

sources: IVD: ce438fd6-8898-11e7-a432-000c2975a0fc

CVSS

SEVERITY

CVSSV2

CVSSV3

IVD: ce438fd6-8898-11e7-a432-000c2975a0fc
value: CRITICAL

Trust: 0.2

IVD: ce438fd6-8898-11e7-a432-000c2975a0fc
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.3 [IVD]

Trust: 0.2

sources: IVD: ce438fd6-8898-11e7-a432-000c2975a0fc

TYPE

Input validation

Trust: 0.2

sources: IVD: ce438fd6-8898-11e7-a432-000c2975a0fc

EXTERNAL IDS

db:IVDid:CE438FD6-8898-11E7-A432-000C2975A0FC

Trust: 0.2

sources: IVD: ce438fd6-8898-11e7-a432-000c2975a0fc

SOURCES

db:IVDid:ce438fd6-8898-11e7-a432-000c2975a0fc

LAST UPDATE DATE

2022-05-04T09:12:55.323000+00:00


SOURCES UPDATE DATE


SOURCES RELEASE DATE

db:IVDid:ce438fd6-8898-11e7-a432-000c2975a0fcdate:2011-06-10T00:00:00