Denial-of-Service Vulnerability in SIMATIC S7-PLCSIM by Siemens
CVE-2021-25673

5.5MEDIUM

Key Information:

Vendor
Siemens
Vendor
CVE Published:
15 March 2021

Summary

A vulnerability exists in SIMATIC S7-PLCSIM V5.4 that allows an attacker with local access to create a Denial-of-Service condition. If a specially crafted file is opened in the application, it may trigger an infinite loop, rendering the application unresponsive. The application will need to be restarted to restore its functionality, leading to potential disruptions in service.

Affected Version(s)

SIMATIC S7-PLCSIM V5.4 All versions

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.