CVE-2021-40368
Description
A vulnerability has been identified in SIMATIC S7-400 CPU 412-1 DP V7 (All versions), SIMATIC S7-400 CPU 412-2 DP V7 (All versions), SIMATIC S7-400 CPU 412-2 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 414-2 DP V7 (All versions), SIMATIC S7-400 CPU 414-3 DP V7 (All versions), SIMATIC S7-400 CPU 414-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 414F-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 416-2 DP V7 (All versions), SIMATIC S7-400 CPU 416-3 DP V7 (All versions), SIMATIC S7-400 CPU 416-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 416F-2 DP V7 (All versions), SIMATIC S7-400 CPU 416F-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 417-4 DP V7 (All versions), SIMATIC S7-400 H V6 CPU family (incl. SIPLUS variants) (All versions < V6.0.10), SIMATIC S7-410 V10 CPU family (incl. SIPLUS variants) (All versions < V10.1), SIMATIC S7-410 V8 CPU family (incl. SIPLUS variants) (All versions < V8.2.3), SIPLUS S7-400 CPU 414-3 PN/DP V7 (All versions < V7.0.3), SIPLUS S7-400 CPU 416-3 PN/DP V7 (All versions < V7.0.3), SIPLUS S7-400 CPU 416-3 V7 (All versions), SIPLUS S7-400 CPU 417-4 V7 (All versions). Affected devices improperly handle specially crafted packets sent to port 102/tcp.
This could allow an attacker to create a Denial-of-Service condition. A restart is needed to restore normal operations.
Affected products
26- cpe:2.3:o:siemens:simatic_s7-400_pn\/dp_v7_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:siemens:simatic_s7-400h_v6_firmware:*:*:*:*:*:*:*:*Range: <6.0.10
- cpe:2.3:o:siemens:simatic_s7-410_v10_firmware:*:*:*:*:*:*:*:*Range: <10.1
- cpe:2.3:o:siemens:simatic_s7-410_v8_firmware:*:*:*:*:*:*:*:*
- Range: All versions
All versions+ 3 more
- (no CPE)range: All versions
- (no CPE)range: All versions
- (no CPE)range: All versions
- (no CPE)range: All versions < V7.0.3
All versions+ 4 more
- (no CPE)range: All versions
- (no CPE)range: All versions
- (no CPE)range: All versions < V7.0.3
- (no CPE)range: All versions
- (no CPE)range: All versions < V7.0.3
- Range: All versions < V7.0.3
All versions+ 3 more
- (no CPE)range: All versions
- (no CPE)range: All versions
- (no CPE)range: All versions < V7.0.3
- (no CPE)range: All versions < V7.0.3
All versions+ 1 more
- (no CPE)range: All versions
- (no CPE)range: All versions < V7.0.3
All versions < V6.0.10+ 2 more
- (no CPE)range: All versions < V6.0.10
- (no CPE)range: All versions < V10.1
- (no CPE)range: All versions < V8.2.3
- Siemens/SIPLUS S7-400 CPU 416-3 V7v5Range: All versions
- Siemens/SIPLUS S7-400 CPU 417-4 V7v5Range: All versions
Patches
Vulnerability mechanics
References
1- cert-portal.siemens.com/productcert/pdf/ssa-557541.pdfnvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.