QID 591120

Date Published: 2022-10-14

QID 591120: Siemens SIMATIC S7-300 CPU Denial of Service (DoS) Vulnerability (ICSA-15-064-04,ssa-987029)

AFFECTED PRODUCTS
The following SIMATIC S7-300 CPUs are affected:SIMATIC S7-300 CPU family: all versions.

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

This vulnerability could allow attackers to perform a DoS attack over the network without prior authentication against S7-300 CPUs under certain conditions. A cold restart is required to recover the system

  • CVSS V3 rated as Low - 0 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-15-064-04 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591120

    Software Advisories
    Advisory ID Software Component Link