QID 591022

Date Published: 2022-09-05

QID 591022: Siemens SIMATIC S7-400 PN CPU Denial of Service (DoS) Vulnerability (SSA-617264) (ICSA-12-212-02)

Affected Products
SIMATIC S7-400 CPU 414-3 PN/DP (6ES7414-3EM05-0AB0): All versions SIMATIC S7-400 CPU 416-3 PN/DP (6ES7416-3ER05-0AB0, incl. SIPLUS variant):All versions SIMATIC S7-400 CPU 416F-3 PN/DP (6ES7416-3FR05-0AB0):All versions

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

When specially crafted packets are received on Ethernet interfaces by the SIMATIC S7-400, the device can default into defect mode. A PLC in defect mode needs to be manually reset to return to normal operation.

  • CVSS V3 rated as Low - 0 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section SSA-617264 for affected packages and patching details.

    CVEs related to QID 591022

    Software Advisories
    Advisory ID Software Component Link
    ICSA-12-212-02 URL Logo www.us-cert.gov/ics/advisories/ICSA-12-212-02
    ssa-617264 URL Logo cert-portal.siemens.com/productcert/pdf/ssa-617264.pdf