Denial of Service Vulnerability in EN100 Ethernet Module by Siemens
CVE-2018-11452
Key Information:
Summary
A vulnerability exists in the EN100 Ethernet module by Siemens, affecting multiple firmware variants. Adversaries can exploit this vulnerability by sending specially crafted packets to port 102/tcp, leading to a denial-of-service condition when oscillographs are operational. Recovery of the module requires a manual restart, as the attack disrupts the network functionality without needing user interaction or privileges. For successful exploitation, the IEC 61850-MMS communication must be activated on affected modules. Comprehensive details are available in advisory publications.
Affected Version(s)
Firmware variant DNP3 TCP for EN100 Ethernet module All versions
Firmware variant IEC 61850 for EN100 Ethernet module All versions < V4.33
Firmware variant IEC104 for EN100 Ethernet module All versions < V1.22
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved