QID 591243

Date Published: 2022-12-23

QID 591243: Siemens SIMATIC S7-1200/1500 CPU family Resource Exhaustion Vulnerability (ICSA-18-317-05, SSA-584286)

AFFECTED PRODUCTS
SIMATIC S7-1200 CPU family (incl. SIPLUS variants): All Versions prior to V4.3
SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants): All Versions prior to V2.6

QID Detection Logic:
This QID checks for the Vulnerable version of Siemens SIMATIC S7-1200/1500 CPU family using passive scanning

Successful exploitation of this vulnerability could result in a denial-of-service condition that could result in a loss of availability of the affected device.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to Cert MITIGATIONS section ICSA-18-317-05 or Siemens MITIGATIONS section SSA-584286 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591243

    Software Advisories
    Advisory ID Software Component Link
    ICSA-18-317-05 URL Logo www.cisa.gov/uscert/ics/advisories/ICSA-18-317-05
    ssa-584286 URL Logo cert-portal.siemens.com/productcert/pdf/ssa-584286.pdf