Denial of Service Vulnerability in Siemens PROFINET Products
CVE-2017-2680
Key Information:
Summary
This vulnerability allows specially crafted PROFINET DCP broadcast packets to induce a denial of service condition on affected Siemens products operating within a local Ethernet segment (Layer 2). Recovery from this state necessitates human intervention. Devices employing PROFIBUS interfaces remain unaffected. It is important for organizations utilizing Siemens PROFINET devices to assess their network security measures and implement strategies to mitigate potential risks associated with this flaw.
Affected Version(s)
Development/Evaluation Kits for PROFINET IO: DK Standard Ethernet Controller All versions < V4.1.1 Patch04
Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200 All versions < V4.2.1 Patch03
Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200P All versions < V4.4.0 Patch01
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved