CVE-2018-13815
Published on: 12/13/2018 12:00:00 AM UTC
Last Modified on: 03/23/2021 11:24:28 PM UTC
Certain versions of Simatic S7-1200 from Siemens contain the following vulnerability:
A vulnerability has been identified in SIMATIC S7-1200 (All versions), SIMATIC S7-1500 (All Versions < V2.6). An attacker could exhaust the available connection pool of an affected device by opening a sufficient number of connections to the device. Successful exploitation requires an attacker to be able to send packets to port 102/tcp of the affected device. No user interaction and no user privileges are required to exploit the vulnerability. The vulnerability, if exploited, could cause a Denial-of-Service condition impacting the availability of the system. At the time of advisory publication no public exploitation of this vulnerability was known.
- CVE-2018-13815 has been assigned by
productc[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
Siemens AG - SIMATIC S7-1200, SIMATIC S7-1500 version SIMATIC S7-1200 : All versions
- Affected Vendor/Software:
Siemens AG - SIMATIC S7-1200, SIMATIC S7-1500 version SIMATIC S7-1500 : All Versions < V2.6
CVSS3 Score: 7.5 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | NONE | HIGH |
CVSS2 Score: 5 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | NONE | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Siemens SIMATIC S7 CVE-2018-13815 Denial of Service Vulnerability | Third Party Advisory VDB Entry cve.report (archive) text/html |
![]() |
Vendor Advisory cert-portal.siemens.com application/pdf |
![]() |
Related QID Numbers
- 591243 Siemens SIMATIC S7-1200/1500 CPU family Resource Exhaustion Vulnerability (ICSA-18-317-05, SSA-584286)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware
| Siemens | Simatic S7-1200 | - | All | All | All |
Hardware
| Siemens | Simatic S7-1200 | - | All | All | All |
Operating System | Siemens | Simatic S7-1200 Firmware | - | All | All | All |
Operating System | Siemens | Simatic S7-1200 Firmware | - | All | All | All |
Hardware
| Siemens | Simatic S7-1500 | - | All | All | All |
Hardware
| Siemens | Simatic S7-1500 | - | All | All | All |
Operating System | Siemens | Simatic S7-1500 Firmware | All | All | All | All |
Operating System | Siemens | Simatic S7-1500 Firmware | All | All | All | All |
- cpe:2.3:h:siemens:simatic_s7-1200:-:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:simatic_s7-1200:-:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:simatic_s7-1200_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:simatic_s7-1200_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:simatic_s7-1500:-:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:simatic_s7-1500:-:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:simatic_s7-1500_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:simatic_s7-1500_firmware:*:*:*:*:*:*:*:*: