CVE-2020-7584

A vulnerability has been identified in SIMATIC S7-200 SMART CPU family (All versions >= V2.2 < V2.5.1). Affected devices do not properly handle large numbers of new incomming connections and could crash under certain circumstances. An attacker may leverage this to cause a Denial-of-Service situation.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:siemens:simatic_s7-200_smart_sr_cpu_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_s7-200_smart_sr_cpu:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:siemens:simatic_s7-200_smart_st_cpu_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_s7-200_smart_st_cpu:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:37

Type Values Removed Values Added
References () https://cert-portal.siemens.com/productcert/pdf/ssa-589181.pdf - Vendor Advisory () https://cert-portal.siemens.com/productcert/pdf/ssa-589181.pdf - Vendor Advisory

Information

Published : 2020-07-14 14:15

Updated : 2024-11-21 05:37


NVD link : CVE-2020-7584

Mitre link : CVE-2020-7584

CVE.ORG link : CVE-2020-7584


JSON object : View

Products Affected

siemens

  • simatic_s7-200_smart_st_cpu_firmware
  • simatic_s7-200_smart_st_cpu
  • simatic_s7-200_smart_sr_cpu_firmware
  • simatic_s7-200_smart_sr_cpu
CWE
CWE-400

Uncontrolled Resource Consumption