Denial of Service Vulnerability in Siemens Devices Due to Improper Packet Handling
CVE-2021-44693
4.9MEDIUM
Key Information:
Summary
Certain Siemens devices fail to correctly handle specially crafted packets directed at port 102/tcp. This flaw can be exploited by an attacker to disrupt normal operations, leading to a denial of service condition. Organizations using affected Siemens products should review their network configurations and apply recommended mitigations to safeguard against potential exploitation.
Affected Version(s)
SIMATIC Drive Controller CPU 1504D TF All versions < V2.9.7
SIMATIC Drive Controller CPU 1507D TF All versions < V2.9.7
SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) All versions < V21.9.7
References
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved