ID

VAR-201107-0313


TITLE

Siemens SIMATIC Controller password protection vulnerability

Trust: 0.2

sources: IVD: 89b248f4-8897-11e7-a432-000c2975a0fc

DESCRIPTION

Siemens SIMATIC S7 series PLC Used in various industrial fields, including energy, water conservancy, oil, natural gas, chemical, building automation, and manufacturing. Siemens PLC Password protection configuration is vulnerable to replay attacks, and PLC Or automated networks can intercept PLC Password, and PLC Make unauthorized changes.

Trust: 0.2

sources: IVD: 89b248f4-8897-11e7-a432-000c2975a0fc

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.2

sources: IVD: 89b248f4-8897-11e7-a432-000c2975a0fc

AFFECTED PRODUCTS

vendor:siemensmodel: - scope:eqversion:*

Trust: 0.8

vendor:siemensmodel:simatic s7-300;scope:eqversion:*

Trust: 0.2

vendor:siemensmodel:simatic s7-400;scope:eqversion:*

Trust: 0.2

vendor:siemensmodel:simatic s7-200;scope:eqversion:*

Trust: 0.2

vendor:siemensmodel:simatic s7-1200;scope:eqversion:*

Trust: 0.2

sources: IVD: 89b248f4-8897-11e7-a432-000c2975a0fc

CVSS

SEVERITY

CVSSV2

CVSSV3

IVD: 89b248f4-8897-11e7-a432-000c2975a0fc
value: CRITICAL

Trust: 0.2

IVD: 89b248f4-8897-11e7-a432-000c2975a0fc
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.3 [IVD]

Trust: 0.2

sources: IVD: 89b248f4-8897-11e7-a432-000c2975a0fc

TYPE

Weak authentication

Trust: 0.2

sources: IVD: 89b248f4-8897-11e7-a432-000c2975a0fc

EXTERNAL IDS

db:IVDid:89B248F4-8897-11E7-A432-000C2975A0FC

Trust: 0.2

sources: IVD: 89b248f4-8897-11e7-a432-000c2975a0fc

SOURCES

db:IVDid:89b248f4-8897-11e7-a432-000c2975a0fc

LAST UPDATE DATE

2022-05-04T10:20:09.620000+00:00


SOURCES UPDATE DATE


SOURCES RELEASE DATE

db:IVDid:89b248f4-8897-11e7-a432-000c2975a0fcdate:2011-07-05T00:00:00