QID 591197
Date Published: 2022-11-25
QID 591197: Siemens SIMATIC S7-300 Denial of Service (DoS) Vulnerability (ICSA-16-161-01, SSA-818183)
AFFECTED PRODUCTS
Siemens reports that the vulnerability affects the following products:
SIMATIC S7-300 CPUs with Profinet support: All versions prior to V3.2.12, and
SIMATIC S7-300 CPUs without Profinet support: All versions prior to V3.3.12.
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
An exploit of this vulnerability could cause the affected device to go into defect mode, requiring a cold restart to recover the system.
Solution
Customers are advised to refer to CERT MITIGATIONS section ICSA-16-161-01 for affected packages and patching details.
Vendor References
- ICSA-16-161-01 -
www.cisa.gov/uscert/ics/advisories/ICSA-16-161-01
CVEs related to QID 591197
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ICSA-16-161-01 |
|
||
| SSA-818183 |
|