ID

VAR-201904-1576


TITLE

S7 300 CPU319-3 / CP343-1 Denial of Service Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2019-10444

DESCRIPTION

Siemens (China) Co., Ltd. is specialized in the fields of electrification, automation and digitization. S7 300 CPU319-3 / CP343-1 has a denial of service vulnerability. An attacker can cause the PLC CPU module and CP module to go down. You need to restart the PLC manually to recover. Other sub-function codes that can trigger the vulnerability include 03/12/15/18

Trust: 0.72

sources: CNVD: CNVD-2019-10444 // IVD: 89eee704-e179-435a-9886-1963ed4bfa99

IOT TAXONOMY

category:['ICS', 'Network device']sub_category: -

Trust: 0.6

category:['ICS']sub_category: -

Trust: 0.2

sources: IVD: 89eee704-e179-435a-9886-1963ed4bfa99 // CNVD: CNVD-2019-10444

AFFECTED PRODUCTS

vendor:siemensmodel:cpu319-3 cp343-1 cpuscope:eqversion:/319-3v3.2.14

Trust: 0.6

vendor:siemensmodel:cpu319-3/cp343-1 cpuscope:eqversion:319-3v3.2.14

Trust: 0.2

sources: IVD: 89eee704-e179-435a-9886-1963ed4bfa99 // CNVD: CNVD-2019-10444

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2019-10444
value: MEDIUM

Trust: 0.6

IVD: 89eee704-e179-435a-9886-1963ed4bfa99
value: MEDIUM

Trust: 0.2

CNVD: CNVD-2019-10444
severity: MEDIUM
baseScore: 6.1
vectorString: AV:A/AC:L/AU:N/C:N/I:N/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: 89eee704-e179-435a-9886-1963ed4bfa99
severity: MEDIUM
baseScore: 6.1
vectorString: AV:A/AC:L/AU:N/C:N/I:N/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: 89eee704-e179-435a-9886-1963ed4bfa99 // CNVD: CNVD-2019-10444

TYPE

Denial of service

Trust: 0.2

sources: IVD: 89eee704-e179-435a-9886-1963ed4bfa99

PATCH

title:S7 300 CPU319-3 / CP343-1 Denial of Service Vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/156959

Trust: 0.6

sources: CNVD: CNVD-2019-10444

EXTERNAL IDS

db:CNVDid:CNVD-2019-10444

Trust: 0.8

db:IVDid:89EEE704-E179-435A-9886-1963ED4BFA99

Trust: 0.2

sources: IVD: 89eee704-e179-435a-9886-1963ed4bfa99 // CNVD: CNVD-2019-10444

SOURCES

db:IVDid:89eee704-e179-435a-9886-1963ed4bfa99
db:CNVDid:CNVD-2019-10444

LAST UPDATE DATE

2022-05-17T01:43:07.243000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2019-10444date:2019-05-07T00:00:00

SOURCES RELEASE DATE

db:IVDid:89eee704-e179-435a-9886-1963ed4bfa99date:2019-04-18T00:00:00
db:CNVDid:CNVD-2019-10444date:2019-05-07T00:00:00