Denial of Service Vulnerability in Siemens Products
CVE-2021-44695

4.9MEDIUM

Summary

Certain Siemens devices are vulnerable to a denial of service attack when processing specifically crafted packets sent to port 102/tcp. This flaw can prevent affected devices from functioning correctly, potentially leading to disruption of services. Organizations using these devices should implement mitigations to reduce exposure to such attacks.

Affected Version(s)

SIMATIC Drive Controller CPU 1504D TF All versions < V2.9.7

SIMATIC Drive Controller CPU 1507D TF All versions < V2.9.7

SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) All versions < V21.9.7

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.