漏洞标题
N/A
漏洞描述信息
已发现SIMATIC S7-400 CPU 412-1 DP V7(所有版本)、SIMATIC S7-400 CPU 412-2 DP V7(所有版本)、SIMATIC S7-400 CPU 412-2 PN/DP V7(所有版本<V7.0.3)、SIMATIC S7-400 CPU 414-2 DP V7(所有版本)、SIMATIC S7-400 CPU 414-3 DP V7(所有版本)、SIMATIC S7-400 CPU 414-3 PN/DP V7(所有版本<V7.0.3)、SIMATIC S7-400 CPU 414F-3 PN/DP V7(所有版本<V7.0.3)、SIMATIC S7-400 CPU 416-2 DP V7(所有版本)、SIMATIC S7-400 CPU 416-3 DP V7(所有版本)、SIMATIC S7-400 CPU 416-3 PN/DP V7(所有版本<V7.0.3)、SIMATIC S7-400 CPU 416F-2 DP V7(所有版本)、SIMATIC S7-400 CPU 416F-3 PN/DP V7(所有版本<V7.0.3)、SIMATIC S7-400 CPU 417-4 DP V7(所有版本)、SIMATIC S7-400 H V6 CPU家族(包括SIPLUS变种)(所有版本<V6.0.10)、SIMATIC S7-410 V10 CPU家族(包括SIPLUS变种)(所有版本<V10.1)、SIMATIC S7-410 V8 CPU家族(包括SIPLUS变种)(所有版本<V8.2.3)、SIPLUS S7-400 CPU 414-3 PN/DP V7(所有版本<V7.0.3)、SIPLUS S7-400 CPU 416-3 PN/DP V7(所有版本<V7.0.3)、SIPLUS S7-400 CPU 416-3 V7(所有版本)、SIPLUS S7-400 CPU 417-4 V7(所有版本)。受影响的设备不正确处理发送到端口102/tcp的特别构造的 packets。
这可能导致攻击者创建拒绝服务条件。需要重启才能恢复正常操作。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
漏洞类别
N/A
漏洞标题
N/A
漏洞描述信息
A vulnerability has been identified in SIMATIC S7-400 CPU 412-1 DP V7 (All versions), SIMATIC S7-400 CPU 412-2 DP V7 (All versions), SIMATIC S7-400 CPU 412-2 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 414-2 DP V7 (All versions), SIMATIC S7-400 CPU 414-3 DP V7 (All versions), SIMATIC S7-400 CPU 414-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 414F-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 416-2 DP V7 (All versions), SIMATIC S7-400 CPU 416-3 DP V7 (All versions), SIMATIC S7-400 CPU 416-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 416F-2 DP V7 (All versions), SIMATIC S7-400 CPU 416F-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 417-4 DP V7 (All versions), SIMATIC S7-400 H V6 CPU family (incl. SIPLUS variants) (All versions < V6.0.10), SIMATIC S7-410 V10 CPU family (incl. SIPLUS variants) (All versions < V10.1), SIMATIC S7-410 V8 CPU family (incl. SIPLUS variants) (All versions < V8.2.3), SIPLUS S7-400 CPU 414-3 PN/DP V7 (All versions < V7.0.3), SIPLUS S7-400 CPU 416-3 PN/DP V7 (All versions < V7.0.3), SIPLUS S7-400 CPU 416-3 V7 (All versions), SIPLUS S7-400 CPU 417-4 V7 (All versions). Affected devices improperly handle specially crafted packets sent to port 102/tcp.
This could allow an attacker to create a Denial-of-Service condition. A restart is needed to restore normal operations.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
漏洞类别
内存缓冲区边界内操作的限制不恰当
漏洞标题
Siemens SIMATIC S7-400 缓冲区错误漏洞
漏洞描述信息
Siemens SIMATIC S7-400是德国西门子(Siemens)公司的一款用于制造和过程自动化领域的可编程逻辑控制器产品。 Siemens SIMATIC S7-400 CPU 存在缓冲区错误漏洞,该漏洞源于产品缺少对于输入的验证。攻击者利用该漏洞可以进行拒绝服务攻击。
CVSS信息
N/A
漏洞类别
缓冲区错误