Lucene search

K
cveSiemensCVE-2018-16558
HistoryApr 17, 2019 - 2:29 p.m.

CVE-2018-16558

2019-04-1714:29:03
CWE-20
siemens
web.nvd.nist.gov
27
cve-2018-16558
simatic s7-1500
vulnerability
dos
network packets
security vulnerability
nvd
cve

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.3

Confidence

High

EPSS

0.002

Percentile

59.8%

A vulnerability has been identified in SIMATIC S7-1500 CPU (All versions >= V2.0 and < V2.5), SIMATIC S7-1500 CPU (All versions <= V1.8.5). Specially crafted network packets sent to port 80/tcp or 443/tcp could allow an unauthenticated remote attacker to cause a Denial-of-Service condition of the device. The security vulnerability could be exploited by an attacker with network access to the affected systems on port 80/tcp or 443/tcp. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise availability of the device. At the time of advisory publication no public exploitation of this security vulnerability was known.

Affected configurations

Nvd
Node
siemenssimatic_s7-1500_firmwareRange1.8.5
OR
siemenssimatic_s7-1500_firmwareRange2.02.5
AND
siemenssimatic_s7-1500Match-
VendorProductVersionCPE
siemenssimatic_s7-1500_firmware*cpe:2.3:o:siemens:simatic_s7-1500_firmware:*:*:*:*:*:*:*:*
siemenssimatic_s7-1500-cpe:2.3:h:siemens:simatic_s7-1500:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "SIMATIC S7-1500 CPU",
    "vendor": "Siemens",
    "versions": [
      {
        "status": "affected",
        "version": "All versions >= V2.0 and < V2.5"
      }
    ]
  },
  {
    "product": "SIMATIC S7-1500 CPU",
    "vendor": "Siemens",
    "versions": [
      {
        "status": "affected",
        "version": "All versions <= V1.8.5"
      }
    ]
  }
]

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.3

Confidence

High

EPSS

0.002

Percentile

59.8%

Related for CVE-2018-16558