CVE-2020-15783

A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC TDC CPU555 (All versions), SINUMERIK 840D sl (All versions). Sending multiple specially crafted packets to the affected devices could cause a Denial-of-Service on port 102. A cold restart is required to recover the service.
References
Link Resource
https://cert-portal.siemens.com/productcert/pdf/ssa-492828.pdf Mitigation Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:siemens:sinumerik_840d_sl_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:sinumerik_840d_sl:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:siemens:simatic_s7-300_cpu_312_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_s7-300_cpu_312:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:siemens:simatic_s7-300_cpu_314_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_s7-300_cpu_314:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:siemens:simatic_s7-300_cpu_315-2_dp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_s7-300_cpu_315-2_dp:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:siemens:simatic_s7-300_cpu_315-2_pn_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_s7-300_cpu_315-2_pn:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:siemens:simatic_s7-300_cpu_317-2_pn_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_s7-300_cpu_317-2_pn:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:siemens:simatic_s7-300_cpu_317-2_dp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_s7-300_cpu_317-2_dp:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:siemens:simatic_s7-300_cpu_315f-2_dp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_s7-300_cpu_315f-2_dp:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:siemens:simatic_s7-300_cpu_315f-2_pn_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_s7-300_cpu_315f-2_pn:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:siemens:simatic_s7-300_cpu_317f-2_pn_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_s7-300_cpu_317f-2_pn:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:siemens:simatic_s7-300_cpu_317f-2_dp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_s7-300_cpu_317f-2_dp:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:siemens:simatic_tdc_cpu555_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_tdc_cpu555:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2020-11-12 20:15

Updated : 2024-02-28 18:08


NVD link : CVE-2020-15783

Mitre link : CVE-2020-15783

CVE.ORG link : CVE-2020-15783


JSON object : View

Products Affected

siemens

  • simatic_tdc_cpu555_firmware
  • simatic_s7-300_cpu_314_firmware
  • simatic_s7-300_cpu_315f-2_dp
  • simatic_s7-300_cpu_317-2_pn
  • simatic_s7-300_cpu_317f-2_dp_firmware
  • simatic_s7-300_cpu_315-2_dp_firmware
  • simatic_s7-300_cpu_317f-2_pn
  • sinumerik_840d_sl
  • simatic_s7-300_cpu_312
  • simatic_s7-300_cpu_315-2_dp
  • sinumerik_840d_sl_firmware
  • simatic_s7-300_cpu_317f-2_pn_firmware
  • simatic_s7-300_cpu_314
  • simatic_tdc_cpu555
  • simatic_s7-300_cpu_317f-2_dp
  • simatic_s7-300_cpu_317-2_dp
  • simatic_s7-300_cpu_315-2_pn
  • simatic_s7-300_cpu_315-2_pn_firmware
  • simatic_s7-300_cpu_317-2_pn_firmware
  • simatic_s7-300_cpu_315f-2_pn
  • simatic_s7-300_cpu_317-2_dp_firmware
  • simatic_s7-300_cpu_312_firmware
  • simatic_s7-300_cpu_315f-2_dp_firmware
  • simatic_s7-300_cpu_315f-2_pn_firmware
CWE
CWE-400

Uncontrolled Resource Consumption