ID

VAR-201510-0732


TITLE

Siemens SIMATIC S7-300 CPU OB Module Security Vulnerability

Trust: 0.2

sources: IVD: 5fd66f78-8898-11e7-a432-000c2975a0fc

DESCRIPTION

Siemens SIMATIC S7-300 CPU device Is the German Siemens ( Siemens ) A modular universal controller for discrete and continuous control of industrial environments, such as manufacturing, food and beverage and chemical industries. S7-300 PLC The program uses a structured program, which is divided into multiple modules, and each module completes the corresponding function. Combined to achieve a complex control system. Just like high-level languages, subroutines are used to implement specific functions, and then each subroutine is called through the main program, so that complex programs can be realized. OB The module is equivalent to the main program and is responsible for calling other modules. Siemens SIMATIC S7-300 CPU Is present in the device OB Module security vulnerability. A remote attacker uses the vulnerability to submit a special sequence of malformed messages and send it to the Ethernet or local serial port, which can cause the application to crash and cause a denial of service attack ( PLC There will be many different reactions, such as denial of service, or inability to download programs, etc.), you need to restart PLC To resume work.

Trust: 0.2

sources: IVD: 5fd66f78-8898-11e7-a432-000c2975a0fc

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.2

sources: IVD: 5fd66f78-8898-11e7-a432-000c2975a0fc

AFFECTED PRODUCTS

vendor:siemensmodel: - scope:eqversion:*

Trust: 0.2

vendor:siemensmodel:simatic s7-300 cpu;scope:eqversion:*

Trust: 0.2

sources: IVD: 5fd66f78-8898-11e7-a432-000c2975a0fc

CVSS

SEVERITY

CVSSV2

CVSSV3

IVD: 5fd66f78-8898-11e7-a432-000c2975a0fc
value: CRITICAL

Trust: 0.2

IVD: 5fd66f78-8898-11e7-a432-000c2975a0fc
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.3 [IVD]

Trust: 0.2

sources: IVD: 5fd66f78-8898-11e7-a432-000c2975a0fc

TYPE

Denial of service

Trust: 0.2

sources: IVD: 5fd66f78-8898-11e7-a432-000c2975a0fc

EXTERNAL IDS

db:IVDid:5FD66F78-8898-11E7-A432-000C2975A0FC

Trust: 0.2

sources: IVD: 5fd66f78-8898-11e7-a432-000c2975a0fc

SOURCES

db:IVDid:5fd66f78-8898-11e7-a432-000c2975a0fc

LAST UPDATE DATE

2022-05-04T10:27:06.192000+00:00


SOURCES UPDATE DATE


SOURCES RELEASE DATE

db:IVDid:5fd66f78-8898-11e7-a432-000c2975a0fcdate:2015-10-01T00:00:00