As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens’ ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: Simantic S7-1500 CPU family
- Vulnerability: Use After Free
2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition.
3. TECHNICAL DETAILS
3.1 AFFECTED PRODUCTS
The following Siemens products are affected:
- SIMATIC Drive Controller CPU 1504D TF (6ES7615-4DF10-0AB0): All versions prior to V3.1.0
- SIMATIC Drive Controller CPU 1507D TF (6ES7615-7DF10-0AB0): All versions prior to V3.1.0
- SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants): All versions
- SIMATIC S7-1500 CPU 1510SP F-1 PN (6ES7510-1SJ00-0AB0): All versions
- SIMATIC S7-1500 CPU 1510SP F-1 PN (6ES7510-1SJ01-0AB0): All versions
- SIMATIC S7-1500 CPU 1510SP F-1 PN (6ES7510-1SK03-0AB0): All versions prior to V3.1.0
- SIMATIC S7-1500 CPU 1510SP-1 PN (6ES7510-1DJ00-0AB0): All versions
- SIMATIC S7-1500 CPU 1510SP-1 PN (6ES7510-1DJ01-0AB0): All versions
- SIMATIC S7-1500 CPU 1510SP-1 PN (6ES7510-1DK03-0AB0): All versions prior to V3.1.0
- SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AK00-0AB0): All versions
- SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AK01-0AB0): All versions
- SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AK02-0AB0): All versions
- SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AL03-0AB0): All versions prior to V3.1.0
- SIMATIC S7-1500 CPU 1511C-1 PN (6ES7511-1CK00-0AB0): All versions
- SIMATIC S7-1500 CPU 1511C-1 PN (6ES7511-1CK01-0AB0): All versions
- SIMATIC S7-1500 CPU 1511C-1 PN (6ES7511-1CL03-0AB0
[…]
Content was cut in order to protect the source.Please visit the source for the rest of the article.This article has been indexed from All CISA AdvisoriesRead the original article: