CVE Database
/

CVE-2017-2680

Back to search

CVE-2017-2680

Published: May 11, 2017

Modified: Sep 10, 2024

PUBLISHED

CVSS v3.1

6.5

MEDIUM

Description

Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2). Human interaction is required to recover the systems. PROFIBUS interfaces are not affected.

VendorProductVersions

Siemens

Development/Evaluation Kits for PROFINET IO: DK Standard Ethernet Controller

affected
All versions < V4.1.1 Patch04

Siemens

Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200

affected
All versions < V4.2.1 Patch03

Siemens

Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200P

affected
All versions < V4.4.0 Patch01

Siemens

Extension Unit 12" PROFINET

affected
All versions < V01.01.01

Siemens

Extension Unit 15" PROFINET

affected
All versions < V01.01.01

Siemens

Extension Unit 19" PROFINET

affected
All versions < V01.01.01

Siemens

Extension Unit 22" PROFINET

affected
All versions < V01.01.01

Siemens

IE/AS-i Link PN IO

affected
All versions

Siemens

IE/PB-Link (incl. SIPLUS NET variants)

affected
All versions < V3.0

Siemens

SCALANCE M-800 family (incl. S615, MUM-800 and RM1224)

affected
All versions < V4.03

Siemens

SCALANCE W-700 IEEE 802.11n family

affected
All versions < V6.1

Siemens

SCALANCE X-200 family (incl. SIPLUS NET variants)

affected
All versions < V5.2.2

Siemens

SCALANCE X-200IRT family (incl. SIPLUS NET variants)

affected
All versions < V5.4.0

Siemens

SCALANCE X-300 family (incl. X408 and SIPLUS NET variants)

affected
All versions < V4.1.0

Siemens

SCALANCE X408 family

affected
All versions < V4.1.0

Siemens

SCALANCE X414

affected
All versions < V3.10.2

Siemens

SCALANCE XM-400 family

affected
All versions < V6.1

Siemens

SCALANCE XR-500 family

affected
All versions < V6.1

Siemens

SIMATIC CM 1542-1

affected
All versions < V2.0

Siemens

SIMATIC CM 1542SP-1

affected
All versions < V1.0.15

Siemens

SIMATIC CP 1242-7 V2 (incl. SIPLUS variants)

affected
All versions < V2.1.82

Siemens

SIMATIC CP 1243-1 (incl. SIPLUS variants)

affected
All versions < V2.1.82

Siemens

SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants)

affected
0 - < *

Siemens

SIMATIC CP 1243-1 IEC (incl. SIPLUS variants)

affected
All versions

Siemens

SIMATIC CP 1243-7 LTE US

affected
All versions < V2.1.82

Siemens

SIMATIC CP 1243-8 IRC

affected
All versions < V2.1.82

Siemens

SIMATIC CP 1243-8 IRC

affected
All versions < V2.1.82

Siemens

SIMATIC CP 1542SP-1 IRC (incl. SIPLUS variants)

affected
All versions < V1.0.15

Siemens

SIMATIC CP 1543-1 (incl. SIPLUS variants)

affected
All versions < V2.1

Siemens

SIMATIC CP 1543SP-1 (incl. SIPLUS variants)

affected
All versions < V1.0.15

Siemens

SIMATIC CP 1604

affected
All versions < V2.7

Siemens

SIMATIC CP 1616

affected
All versions < V2.7

Siemens

SIMATIC CP 1626

affected
All versions < V1.1

Siemens

SIMATIC CP 343-1 (incl. SIPLUS variants)

affected
All versions < V3.1.3

Siemens

SIMATIC CP 343-1 Advanced (incl. SIPLUS variants)

affected
All versions

Siemens

SIMATIC CP 343-1 Lean (incl. SIPLUS variants)

affected
All versions < V3.1.3

Siemens

SIMATIC CP 443-1 (incl. SIPLUS variants)

affected
All versions < V3.2.17

Siemens

SIMATIC CP 443-1 Advanced (incl. SIPLUS variants)

affected
All versions < V3.2.17

Siemens

SIMATIC CP 443-1 OPC UA

affected
All versions

Siemens

SIMATIC DK-16xx PN IO

affected
All versions < V2.7

Siemens

SIMATIC ET 200AL IM 157-1 PN

affected
0 - < V1.0.2

Siemens

SIMATIC ET 200M (incl. SIPLUS variants)

affected
All versions

Siemens

SIMATIC ET 200MP IM 155-5 PN BA

affected
0 - < V4.0.1

Siemens

SIMATIC ET 200MP IM 155-5 PN HF

affected
0 - < V4.2.0

Siemens

SIMATIC ET 200MP IM 155-5 PN ST

affected
0 - < V4.1.0

Siemens

SIMATIC ET 200pro IM 154-3 PN HF

affected
0 - < *

Siemens

SIMATIC ET 200pro IM 154-4 PN HF

affected
0 - < *

Siemens

SIMATIC ET 200SP IM 155-6 PN BA

affected
0 - < *

Siemens

SIMATIC ET 200SP IM 155-6 PN HF

affected
0 - < V4.2.0

Siemens

SIMATIC ET 200SP IM 155-6 PN HS

affected
0 - < V4.0.1

Siemens

SIMATIC ET 200SP IM 155-6 PN ST

affected
0 - < V4.1.0

Siemens

SIMATIC ET 200SP IM 155-6 PN ST BA

affected
0 - < V4.1.0

Siemens

SIMATIC ET200ecoPN, 16DI, DC24V, 8xM12

affected
All versions

Siemens

SIMATIC ET200ecoPN, 16DO DC24V/1,3A, 8xM12

affected
All versions

Siemens

SIMATIC ET200ecoPN, 4AO U/I 4xM12

affected
All versions

Siemens

SIMATIC ET200ecoPN, 8 DIO, DC24V/1,3A, 8xM12

affected
All versions

Siemens

SIMATIC ET200ecoPN, 8 DO, DC24V/2A, 8xM12

affected
All versions

Siemens

SIMATIC ET200ecoPN, 8AI RTD/TC 8xM12

affected
All versions

Siemens

SIMATIC ET200ecoPN, 8AI; 4 U/I; 4 RTD/TC 8xM12

affected
All versions

Siemens

SIMATIC ET200ecoPN, 8DI, DC24V, 4xM12

affected
All versions

Siemens

SIMATIC ET200ecoPN, 8DI, DC24V, 8xM12

affected
All versions

Siemens

SIMATIC ET200ecoPN, 8DO, DC24V/0,5A, 4xM12

affected
All versions

Siemens

SIMATIC ET200ecoPN, 8DO, DC24V/1,3A, 4xM12

affected
All versions

Siemens

SIMATIC ET200ecoPN, 8DO, DC24V/1,3A, 8xM12

affected
All versions

Siemens

SIMATIC ET200ecoPN: IO-Link Master

affected
All versions

Siemens

SIMATIC ET200S (incl. SIPLUS variants)

affected
All versions

Siemens

SIMATIC HMI Comfort Panels, HMI Multi Panels, HMI Mobile Panels (incl. SIPLUS variants)

affected
All versions < V15.1

Siemens

SIMATIC MV420 SR-B

affected
0 - < V7.0.6

Siemens

SIMATIC MV420 SR-B Body

affected
0 - < V7.0.6

Siemens

SIMATIC MV420 SR-P

affected
0 - < V7.0.6

Siemens

SIMATIC MV420 SR-P Body

affected
0 - < V7.0.6

Siemens

SIMATIC MV440 HR

affected
0 - < V7.0.6

Siemens

SIMATIC MV440 SR

affected
0 - < V7.0.6

Siemens

SIMATIC MV440 UR

affected
0 - < V7.0.6

Siemens

SIMATIC PN/PN Coupler (incl. SIPLUS NET variants)

affected
All versions < V4.0

Siemens

SIMATIC RF650R

affected
All versions < V3.0

Siemens

SIMATIC RF680R

affected
All versions < V3.0

Siemens

SIMATIC RF685R

affected
All versions < V3.0

Siemens

SIMATIC S7-1200 CPU family (incl. SIPLUS variants)

affected
All versions < V4.2.1

Siemens

SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants)

affected
All versions < V2.1

Siemens

SIMATIC S7-1500 Software Controller

affected
All versions < V2.1

Siemens

SIMATIC S7-200 SMART

affected
All versions < V2.3

Siemens

SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants)

affected
0 - < V3.X.14

Siemens

SIMATIC S7-400 H V6 CPU family (incl. SIPLUS variants)

affected
0 - < V6.0.7

Siemens

SIMATIC S7-400 PN/DP V6 CPU family (incl. SIPLUS variants)

affected
0 - < V6.0.6

Siemens

SIMATIC S7-400 PN/DP V7 CPU family (incl. SIPLUS variants)

affected
0 - < V7.0.2

Siemens

SIMATIC S7-410 CPU family (incl. SIPLUS variants)

affected
All versions < V8.2

Siemens

SIMATIC TDC CP51M1

affected
0 - < V1.1.8

Siemens

SIMATIC TDC CPU555

affected
0 - < V1.1.1

Siemens

SIMATIC Teleservice Adapter IE Advanced

affected
All versions

Siemens

SIMATIC Teleservice Adapter IE Basic

affected
All versions

Siemens

SIMATIC Teleservice Adapter IE Standard

affected
All versions

Siemens

SIMATIC WinAC RTX 2010

affected
All versions < V2010 SP3

Siemens

SIMATIC WinAC RTX F 2010

affected
All versions < V2010 SP3

Siemens

SIMOCODE pro V PROFINET (incl. SIPLUS variants)

affected
All versions < V2.0.0

Siemens

SIMOTION

affected
All versions < V4.5 HF1

Siemens

SIMOTION D4xx V4.4 for SINAMICS SM150i-2 w. PROFINET (incl. SIPLUS variants)

affected
All versions < V4.4 HF26

Siemens

SINAMICS DCM w. PN

affected
All versions < V1.4 SP1 HF5

Siemens

SINAMICS DCP w. PN

affected
All versions < V1.2 HF1

Siemens

SINAMICS G110M w. PN

affected
All versions < V4.7 SP6 HF3

Siemens

SINAMICS G120(C/P/D) w. PN (incl. SIPLUS variants)

affected
All versions < V4.7 SP6 HF3

Siemens

SINAMICS G130 V4.7 w. PN

affected
All versions < V4.7 HF27

Siemens

SINAMICS G130 V4.8 w. PN

affected
All versions < V4.8 HF4

Siemens

SINAMICS G150 V4.7 w. PN

affected
V4.7: All versions < V4.7 HF27

Siemens

SINAMICS G150 V4.8 w. PN

affected
All versions < V4.8 HF4

Siemens

SINAMICS GH150 V4.7 w. PROFINET

affected
All versions < V4.7 SP5 HF7

Siemens

SINAMICS GL150 V4.7 w. PROFINET

affected
All versions < V4.8 SP2

Siemens

SINAMICS GM150 V4.7 w. PROFINET

affected
All versions < V4.7 HF31

Siemens

SINAMICS S110 w. PN

affected
All versions < V4.4 SP3 HF5

Siemens

SINAMICS S120 prior to V4.7 w. PN (incl. SIPLUS variants)

affected
All versions < V4.7

Siemens

SINAMICS S120 V4.7 SP1 w. PN (incl. SIPLUS variants)

affected
All versions

Siemens

SINAMICS S120 V4.7 w. PN (incl. SIPLUS variants)

affected
All versions < V4.7 HF27

Siemens

SINAMICS S120 V4.8 w. PN (incl. SIPLUS variants)

affected
All versions < V4.8 HF4

Siemens

SINAMICS S150 V4.7 w. PN

affected
All versions < V4.7 HF27

Siemens

SINAMICS S150 V4.8 w. PN

affected
All versions < V4.8 HF4

Siemens

SINAMICS SL150 V4.7.0 w. PROFINET

affected
All versions < V4.7 HF30

Siemens

SINAMICS SL150 V4.7.4 w. PROFINET

affected
All versions < V4.8 SP2

Siemens

SINAMICS SL150 V4.7.5 w. PROFINET

affected
All versions < V4.8 SP2

Siemens

SINAMICS SM120 V4.7 w. PROFINET

affected
All versions < V4.8 SP2

Siemens

SINAMICS V90 w. PN

affected
All versions < V1.01

Siemens

SINUMERIK 828D V4.5 and prior

affected
All versions < V4.5 SP6 HF2

Siemens

SINUMERIK 828D V4.7

affected
All versions < V4.7 SP4 HF1

Siemens

SINUMERIK 840D sl V4.5 and prior

affected
All versions < V4.5 SP6 HF2

Siemens

SINUMERIK 840D sl V4.7

affected
All versions < V4.7 SP4 HF1

Siemens

SIPLUS ET 200MP IM 155-5 PN HF

affected
0 - < V4.2.0

Siemens

SIPLUS ET 200MP IM 155-5 PN HF

affected
0 - < V4.2.0

Siemens

SIPLUS ET 200MP IM 155-5 PN HF T1 RAIL

affected
0 - < V4.2.0

Siemens

SIPLUS ET 200MP IM 155-5 PN ST

affected
0 - < V4.1.0

Siemens

SIPLUS ET 200MP IM 155-5 PN ST TX RAIL

affected
0 - < V4.1.0

Siemens

SIPLUS ET 200SP IM 155-6 PN HF

affected
0 - < V4.2.0

Siemens

SIPLUS ET 200SP IM 155-6 PN HF

affected
0 - < V4.2.0

Siemens

SIPLUS ET 200SP IM 155-6 PN HF T1 RAIL

affected
0 - < V4.2.0

Siemens

SIPLUS ET 200SP IM 155-6 PN ST

affected
0 - < V4.1.0

Siemens

SIPLUS ET 200SP IM 155-6 PN ST BA

affected
0 - < V4.1.0

Siemens

SIPLUS ET 200SP IM 155-6 PN ST BA TX RAIL

affected
0 - < V4.1.0

Siemens

SIPLUS ET 200SP IM 155-6 PN ST TX RAIL

affected
0 - < V4.1.0

Siemens

SIRIUS ACT 3SU1 interface module PROFINET

affected
All versions < V1.1.0

Siemens

SIRIUS Motor Starter M200D PROFINET

affected
All versions

Siemens

SIRIUS Soft Starter 3RW44 PN

affected
All versions

Siemens

SITOP PSU8600 PROFINET

affected
All versions < V1.2.0

Siemens

SITOP UPS1600 PROFINET (incl. SIPLUS variants)

affected
All versions < V2.2.0

Siemens

Softnet PROFINET IO for PC-based Windows systems

affected
All versions < V14 SP1

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector

Adjacent

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

None

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now