Denial-of-Service Vulnerability in Siemens SIMATIC ET 200SP and S7-1500 Products
CVE-2019-19281
Key Information:
Summary
A vulnerability exists in specific Siemens SIMATIC products, including the ET 200SP Open Controller and the S7-1500 CPU family, which allows unauthenticated attackers to initiate a Denial-of-Service condition. This vulnerability is triggered by sending specially crafted UDP packets to the affected devices. Exploitation does not require any system privileges or user interaction, posing a significant risk to device availability and network security.
Affected Version(s)
SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) All versions >= V2.5 and < V20.8
SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants) All versions >= V2.5 and < V2.8
SIMATIC S7-1500 Software Controller All versions >= V2.5 and < V20.8
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved