Denial of Service Vulnerability in EN100 Ethernet Module by Siemens
CVE-2018-11452

7.5HIGH

Summary

A vulnerability exists in the EN100 Ethernet module by Siemens, affecting multiple firmware variants. Adversaries can exploit this vulnerability by sending specially crafted packets to port 102/tcp, leading to a denial-of-service condition when oscillographs are operational. Recovery of the module requires a manual restart, as the attack disrupts the network functionality without needing user interaction or privileges. For successful exploitation, the IEC 61850-MMS communication must be activated on affected modules. Comprehensive details are available in advisory publications.

Affected Version(s)

Firmware variant DNP3 TCP for EN100 Ethernet module All versions

Firmware variant IEC 61850 for EN100 Ethernet module All versions < V4.33

Firmware variant IEC104 for EN100 Ethernet module All versions < V1.22

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.