ID

VAR-201106-0308


TITLE

Siemens SIMATIC PLC Use clear text unverified protocol vulnerability

Trust: 0.2

sources: IVD: ed2eb0d8-8898-11e7-a432-000c2975a0fc

DESCRIPTION

Siemens SIMATIC S7 series PLC Used in various industrial fields, including energy, water conservancy, oil, natural gas, chemical, building automation, and manufacturing. S7-300/400 In the interface, Siemens and non-Siemens products are allowed to use the plaintext protocol. Changing the protocol will cause product compatibility issues.

Trust: 0.2

sources: IVD: ed2eb0d8-8898-11e7-a432-000c2975a0fc

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.2

sources: IVD: ed2eb0d8-8898-11e7-a432-000c2975a0fc

AFFECTED PRODUCTS

vendor:siemensmodel: - scope:eqversion:*

Trust: 0.8

vendor:siemensmodel:simatic s7-300;scope:eqversion:*

Trust: 0.2

vendor:siemensmodel:simatic s7-1200;scope:eqversion:*

Trust: 0.2

vendor:siemensmodel:simatic s7-400;scope:eqversion:*

Trust: 0.2

vendor:siemensmodel:simatic s7-200;scope:eqversion:*

Trust: 0.2

sources: IVD: ed2eb0d8-8898-11e7-a432-000c2975a0fc

CVSS

SEVERITY

CVSSV2

CVSSV3

IVD: ed2eb0d8-8898-11e7-a432-000c2975a0fc
value: LOW

Trust: 0.2

IVD: ed2eb0d8-8898-11e7-a432-000c2975a0fc
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.3 [IVD]

Trust: 0.2

sources: IVD: ed2eb0d8-8898-11e7-a432-000c2975a0fc

TYPE

other

Trust: 0.2

sources: IVD: ed2eb0d8-8898-11e7-a432-000c2975a0fc

EXTERNAL IDS

db:IVDid:ED2EB0D8-8898-11E7-A432-000C2975A0FC

Trust: 0.2

sources: IVD: ed2eb0d8-8898-11e7-a432-000c2975a0fc

SOURCES

db:IVDid:ed2eb0d8-8898-11e7-a432-000c2975a0fc

LAST UPDATE DATE

2022-05-04T09:48:30.502000+00:00


SOURCES UPDATE DATE


SOURCES RELEASE DATE

db:IVDid:ed2eb0d8-8898-11e7-a432-000c2975a0fcdate:2011-06-10T00:00:00