Lucene search

K
cveMitreCVE-2014-2251
HistoryMar 16, 2014 - 2:06 p.m.

CVE-2014-2251

2014-03-1614:06:45
mitre
web.nvd.nist.gov
32
siemens
simatic s7-1500
cpu plc
firmware
vulnerability
cryptographic protection
nvd
cve-2014-2251

CVSS2

8.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:P/I:P/A:C

AI Score

6.7

Confidence

Low

EPSS

0.006

Percentile

77.7%

The random-number generator on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 does not have sufficient entropy, which makes it easier for remote attackers to defeat cryptographic protection mechanisms and hijack sessions via unspecified vectors.

Affected configurations

Nvd
Node
siemenssimatic_s7-1500_cpu_firmwareRange1.1.2
OR
siemenssimatic_s7-1500_cpu_firmwareMatch1.0.1
OR
siemenssimatic_s7-1500_cpu_firmwareMatch1.1.0
OR
siemenssimatic_s7-1500_cpu_firmwareMatch1.1.1
VendorProductVersionCPE
siemenssimatic_s7-1500_cpu_firmware*cpe:2.3:o:siemens:simatic_s7-1500_cpu_firmware:*:*:*:*:*:*:*:*
siemenssimatic_s7-1500_cpu_firmware1.0.1cpe:2.3:o:siemens:simatic_s7-1500_cpu_firmware:1.0.1:*:*:*:*:*:*:*
siemenssimatic_s7-1500_cpu_firmware1.1.0cpe:2.3:o:siemens:simatic_s7-1500_cpu_firmware:1.1.0:*:*:*:*:*:*:*
siemenssimatic_s7-1500_cpu_firmware1.1.1cpe:2.3:o:siemens:simatic_s7-1500_cpu_firmware:1.1.1:*:*:*:*:*:*:*

CVSS2

8.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:P/I:P/A:C

AI Score

6.7

Confidence

Low

EPSS

0.006

Percentile

77.7%