QID 591414

QID 591414: Siemens SIMATIC S7-PLCSIM Advanced Denial of Service (DoS) Vulnerability (SSA-382653)

AFFECTED PRODUCTS
The following Siemens products are affected: SIMATIC S7-PLCSIM Advanced: All versions prior to v5.0

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of Siemens using registry "HKLM\SOFTWARE\Siemens"

Successful exploitation of this vulnerability could allow an unauthenticated attacker to perform a denial-of-service attack under certain conditions.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section SSA-382653 for affected packages and patching details.Workaround:
    Restrict access to port 102/tcp to trusted systems e.g. with an external firewall

    CVEs related to QID 591414

    Software Advisories
    Advisory ID Software Component Link
    SSA-382653 URL Logo cert-portal.siemens.com/productcert/html/ssa-382653.html