CVE-2019-18336
Published on: 03/10/2020 12:00:00 AM UTC
Last Modified on: 03/23/2021 11:28:06 PM UTC
Certain versions of Simatic S7-300 Cpu from Siemens contain the following vulnerability:
A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions < V3.X.17), SIMATIC TDC CP51M1 (All versions < V1.1.8), SIMATIC TDC CPU555 (All versions < V1.1.1), SINUMERIK 840D sl (All versions < V4.8.6), SINUMERIK 840D sl (All versions < V4.94). Specially crafted packets sent to port 102/tcp (Profinet) could cause the affected device to go into defect mode. A restart is required in order to recover the system. Successful exploitation requires an attacker to have network access to port 102/tcp, with no authentication. No user interation is required. At the time of advisory publication no public exploitation of this security vulnerability was known.
- CVE-2019-18336 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
Siemens AG - SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) version All versions < V3.X.17
- Affected Vendor/Software:
Siemens AG - SIMATIC TDC CP51M1 version All versions < V1.1.8
- Affected Vendor/Software:
Siemens AG - SIMATIC TDC CPU555 version All versions < V1.1.1
- Affected Vendor/Software:
Siemens AG - SINUMERIK 840D sl version All versions < V4.8.6
- Affected Vendor/Software:
Siemens AG - SINUMERIK 840D sl version All versions < V4.94
CVSS3 Score: 7.5 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | NONE | HIGH |
CVSS2 Score: 7.8 - HIGH
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | NONE | COMPLETE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Vendor Advisory cert-portal.siemens.com application/pdf |
![]() |
Known Affected Configurations (CPE V2.3)
- cpe:2.3:h:siemens:simatic_s7-300_cpu:-:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:simatic_s7-300_cpu:-:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:simatic_s7-300_cpu_312_ifm:-:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:simatic_s7-300_cpu_312_ifm:-:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:simatic_s7-300_cpu_312_ifm_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:simatic_s7-300_cpu_312_ifm_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:simatic_s7-300_cpu_313:-:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:simatic_s7-300_cpu_313:-:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:simatic_s7-300_cpu_313_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:simatic_s7-300_cpu_313_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:simatic_s7-300_cpu_314:-:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:simatic_s7-300_cpu_314:-:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:simatic_s7-300_cpu_314_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:simatic_s7-300_cpu_314_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:simatic_s7-300_cpu_314_ifm:-:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:simatic_s7-300_cpu_314_ifm:-:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:simatic_s7-300_cpu_314_ifm_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:simatic_s7-300_cpu_314_ifm_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:simatic_s7-300_cpu_315:-:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:simatic_s7-300_cpu_315:-:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:simatic_s7-300_cpu_315-2_dp:-:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:simatic_s7-300_cpu_315-2_dp:-:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:simatic_s7-300_cpu_315-2_dp_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:simatic_s7-300_cpu_315-2_dp_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:simatic_s7-300_cpu_315_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:simatic_s7-300_cpu_315_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:simatic_s7-300_cpu_316-2_dp:-:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:simatic_s7-300_cpu_316-2_dp:-:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:simatic_s7-300_cpu_316-2_dp_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:simatic_s7-300_cpu_316-2_dp_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:simatic_s7-300_cpu_318-2:-:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:simatic_s7-300_cpu_318-2:-:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:simatic_s7-300_cpu_318-2_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:simatic_s7-300_cpu_318-2_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:simatic_s7-300_cpu_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:simatic_s7-300_cpu_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:simatic_tdc_cp51m1:-:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:simatic_tdc_cp51m1:-:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:simatic_tdc_cp51m1_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:simatic_tdc_cp51m1_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:simatic_tdc_cpu555:-:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:simatic_tdc_cpu555:-:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:simatic_tdc_cpu555_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:simatic_tdc_cpu555_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:sinumerik_840d_sl:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:sinumerik_840d_sl:*:*:*:*:*:*:*:*: