QID 591021

Date Published: 2022-09-05

QID 591021: Siemens SIMATIC S7-400 PN CPU Denial of Service (DoS) Vulnerability (ssa-589272) (ICSA-12-212-02)

Affected Products
SIMATIC S7-400 CPU 412-2 PN (6ES7412-2EK06-0AB0, incl. SIPLUS variants): All versions prior to V6.0.3
SIMATIC S7-400 CPU 414-3 PN/DP and CPU414F-3 PN/DP (6ES7414-3EM06-0AB0 and6ES7414-3FM06-0AB0, incl. SIPLUS variants): All versions prior to V6.0.3
SIMATIC S7-400 CPU 416-3 PN/DP and CPU 416F-3 PN (6ES7416-3ES06-0AB0 and 6ES7416-3FS06-0AB0, incl. SIPLUS variants): All versions prior to V6.0.3

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

When specially crafted packets are received on Ethernet interfaces by the SIMATIC S7-400, the device can default into defect mode. A PLC in defect mode needs to be manually reset to return to normal operation.

  • CVSS V3 rated as Low - 0 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ssa-589272 for affected packages and patching details.

    CVEs related to QID 591021

    Software Advisories
    Advisory ID Software Component Link
    ICSA-12-212-02 URL Logo www.us-cert.gov/ics/advisories/ICSA-12-212-02
    ssa-589272 URL Logo cert-portal.siemens.com/productcert/pdf/ssa-589272.pdf