CVE Database
/

CVE-2018-16556

Back to search

CVE-2018-16556

Published: Dec 13, 2018

Modified: Aug 5, 2024

PUBLISHED

CVSS v3.1

7.5

HIGH

Description

A vulnerability has been identified in SIMATIC S7-400 CPU 412-1 DP V7 (All versions), SIMATIC S7-400 CPU 412-2 DP V7 (All versions), SIMATIC S7-400 CPU 414-2 DP V7 (All versions), SIMATIC S7-400 CPU 414-3 DP V7 (All versions), SIMATIC S7-400 CPU 414-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 414F-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 416-2 DP V7 (All versions), SIMATIC S7-400 CPU 416-3 DP V7 (All versions), SIMATIC S7-400 CPU 416-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 416F-2 DP V7 (All versions), SIMATIC S7-400 CPU 416F-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 417-4 DP V7 (All versions), SIMATIC S7-400 CPU 412-2 PN V7 (All versions < V7.0.3), SIMATIC S7-400 H V4.5 and below CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-400 H V6 CPU family (incl. SIPLUS variants) (All versions < V6.0.9), SIMATIC S7-400 PN/DP V6 and below CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-410 CPU family (incl. SIPLUS variants) (All versions < V8.2.1), SIPLUS S7-400 CPU 414-3 PN/DP V7 (All versions < V7.0.3), SIPLUS S7-400 CPU 416-3 PN/DP V7 (All versions < V7.0.3), SIPLUS S7-400 CPU 416-3 V7 (All versions), SIPLUS S7-400 CPU 417-4 V7 (All versions). Specially crafted packets sent to port 102/tcp via Ethernet interface, via PROFIBUS, or via Multi Point Interfaces (MPI) could cause the affected devices to go into defect mode. Manual reboot is required to resume normal operation. Successful exploitation requires an attacker to be able to send specially crafted packets to port 102/tcp via Ethernet interface, via PROFIBUS or Multi Point Interfaces (MPI). No user interaction and no user privileges are required to exploit the security vulnerability. The vulnerability could allow causing a denial of service condition of the core functionality of the CPU, compromising the availability of the system.

VendorProductVersions

Siemens

SIMATIC S7-400 CPU 412-1 DP V7

affected
All versions

Siemens

SIMATIC S7-400 CPU 412-2 DP V7

affected
All versions

Siemens

SIMATIC S7-400 CPU 414-2 DP V7

affected
All versions

Siemens

SIMATIC S7-400 CPU 414-3 DP V7

affected
All versions

Siemens

SIMATIC S7-400 CPU 414-3 PN/DP V7

affected
All versions < V7.0.3

Siemens

SIMATIC S7-400 CPU 414F-3 PN/DP V7

affected
All versions < V7.0.3

Siemens

SIMATIC S7-400 CPU 416-2 DP V7

affected
All versions

Siemens

SIMATIC S7-400 CPU 416-3 DP V7

affected
All versions

Siemens

SIMATIC S7-400 CPU 416-3 PN/DP V7

affected
All versions < V7.0.3

Siemens

SIMATIC S7-400 CPU 416F-2 DP V7

affected
All versions

Siemens

SIMATIC S7-400 CPU 416F-3 PN/DP V7

affected
All versions < V7.0.3

Siemens

SIMATIC S7-400 CPU 417-4 DP V7

affected
All versions

Siemens

SIMATIC S7-400 CPU 412-2 PN V7

affected
All versions < V7.0.3

Siemens

SIMATIC S7-400 H V4.5 and below CPU family (incl. SIPLUS variants)

affected
All versions

Siemens

SIMATIC S7-400 H V6 CPU family (incl. SIPLUS variants)

affected
All versions < V6.0.9

Siemens

SIMATIC S7-400 PN/DP V6 and below CPU family (incl. SIPLUS variants)

affected
All versions

Siemens

SIMATIC S7-410 CPU family (incl. SIPLUS variants)

affected
All versions < V8.2.1

Siemens

SIPLUS S7-400 CPU 414-3 PN/DP V7

affected
All versions < V7.0.3

Siemens

SIPLUS S7-400 CPU 416-3 PN/DP V7

affected
All versions < V7.0.3

Siemens

SIPLUS S7-400 CPU 416-3 V7

affected
All versions

Siemens

SIPLUS S7-400 CPU 417-4 V7

affected
All versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

None

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now