Denial-of-Service Vulnerability in Siemens SIMATIC ET 200SP and S7-1500 Products
CVE-2019-19281

7.5HIGH

Summary

A vulnerability exists in specific Siemens SIMATIC products, including the ET 200SP Open Controller and the S7-1500 CPU family, which allows unauthenticated attackers to initiate a Denial-of-Service condition. This vulnerability is triggered by sending specially crafted UDP packets to the affected devices. Exploitation does not require any system privileges or user interaction, posing a significant risk to device availability and network security.

Affected Version(s)

SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) All versions >= V2.5 and < V20.8

SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants) All versions >= V2.5 and < V2.8

SIMATIC S7-1500 Software Controller All versions >= V2.5 and < V20.8

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.