QID 590796

Date Published: 2023-04-03

QID 590796: Siemens PROFINET Devices (Update C) Vulnerability (ICSA-21-194-03)

AFFECTED PRODUCTS
SIMATIC NET CM 1542-1:All prior to v3.0
SCALANCE X204-2(incl.SIPLUS NET):All prior to v5.2.5
SCALANCE X204-2FM:All prior to v5.2.5
SCALANCE X204-2LD (incl.SIPLUS NET):All prior to v5.2.5
SCALANCE X20204-2LD TS:All prior to v5.2.5
SCALANCE X204 -2TS:All prior to v5.2.5
SCALANCE X206-1:All prior to v5.2.5
SCALANCE X206-1LD (incl. SIPLUS NET):All prior to v5.2.5
SCALANCE X208 (incl. SIPLUS NET):All prior to v5.2.5
SCALANCE X208PRO:All prior to v5.2.5
SCALANCE X212-2:All prior to v5.2.5
SCALANCE X12-2LD:All prior to v5.2.5
SCALANCE X216:All prior to v5.2.5
SCALANCE X224:All prior to v5.2.5
Development/Evaluation Kits for PROFINET IO:DK Standard Ethernet Controller:All versions
Development/Evaluation Kits for PROFINET IO:EK-ERTEC 200:All versions
Development/Evaluation Kits for PROFINET IO:EK-ERTEC 200P:All versions
RUGGEDCOM RM1224:All prior to v6.4
SCALANCE M-800:All prior to v6.4
SCALANCE S615:All prior to v6.4
SCALANCE W700 IEEE 802.11n:All versions
SCALANCE W700 IEEE 802.11ac:All versions
SCALANCE X200-4 P IRT:All prior to v5.5.0
SCALANCE X201-3P IRT:All prior to v5.5.0
SCALANCE X201-3P IRT PRO:All prior to v5.5.0
SCALANCE X202-2 IRT:All prior to v5.5.0
SCALANCE X202-2P IRT (incl. SIPLUS NET):All prior to v5.5.0
SCALANCE X202-2P IRT PRO:All prior to v5.5.0
SCALANCE X204 IRT:All prior to v5.5.0
SCALANCE X204 IRT PRO:All prior to v5.5.0
SCALANCE X204-2 (incl. SIPLUS NET):All versions
SCALANCE X204-2FM:All versions
SCALANCE X204-2LD (incl. SIPLUS NET):All versions
SCALANCE X20204-2LD TS:All versions
SCALANCE X204 -2TS:All versions
SCALANCE X206-1:All versions
SCALANCE X206-1LD (incl. SIPLUS NET):All versions
SCALANCE X208 (incl. SIPLUS NET):All versions
SCALANCE X208PRO:All versions
SCALANCE X212-2:All versions
SCALANCE X12-2LD:All versions
SCALANCE X216:All versions
SCALANCE X224:All versions
SCALANCE X302-7EEC:All versions
SCALANCE 304-2FE:All versions
SCALANCE X306-1LDFE:All versions
SCALANCE X307-2EEC:All versions
SCALANCE X307-3:All versions
SCALANCE X307-3LD:All versions
SCALANCE X308-2 (incl. SIPLUS NET) All versions
SCALANCE X308-2LD:All versions
SCALANCE X308-2LH:All versions
SCALANCE X308-2LH+:All versions
SCALANCE X308-2M:All versions
SCALANCE X308-2M POE:All versions
SCALANCE X308-2M TS:All versions
SCALANCE X310:All versions
SCALANCE X310FE:All versions
SCALANCE X320-1FE:All versions
SCALANCE X320-3LDFE:All versions
SCALANCE XB-200:All versions
SCALANCE XC-200:All versions
SCALANCE XF201-3P IRT:All prior to v5.5.0
SCALANCE XF202-2P IRT:All prior to v5.5.0
SCALANCE XF204:All versions
SCALANCE XF204 IRT:All prior to v5.5.0
SCALANCE XF204-2 (incl. SIPLUS NET):All versions
SCALANCE XF204-2BA IRT:All prior to v5.5.0
SCALANCE XF206-1:All versions
SCALANCE XF208:All versions
SCALANCE XF-200BA:All versions
SCALANCE XM400:All prior to v6.3.1
SCALANCE XP-200:All versions
SCALANCE XR324-4M EEC:All versions
SCALANCE XR324-4M POE:All versions
SCALANCE XR324-4M POE TS:All versions
SCALANCE XR324-12M:All versions
SCALANCE XR324-12M TS:All versions
SCALANCE XR500:All prior to v6.3.1
SCALANCE XR-300WG:All versions
SIMATIC CFU PA:All versions
SIMATIC IE/PB-LINK V3:All versions
SIMATIC MV500 family:All prior to v3.0
SIMATIC NET CM 1542-1:All versions
SIMATIC NET CP1616/CP1604:All Versions 2.7 and prior
SIMATIC NET CP1626:All versions
SIMATIC NET DK-16xx PN IO:All Versions 2.7 and prior
SIMATIC Power Line Booster PLB(MLFB:6ES7972-5AA10-0AB0):All versions
SIMATIC S7-1200 CPU(incl. SIPLUS variants):All prior to v4.5
SIMOCODE proV Ethernet/IP:All prior to v1.1.3
SIMOCODE proV PROFINET:All prior to v2.1.3
SOFTNET-IE PNIO:All versions

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of this vulnerability could allow an attacker to perform a denial-of-service attack if a large amount of PROFINET Discovery and Configuration Protocol (DCP) reset packets is sent to the affected devices.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-21-194-03 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590796

    Software Advisories
    Advisory ID Software Component Link
    ICSA-21-194-03 URL Logo www.us-cert.gov/ics/advisories/ICSA-21-194-03