CVE-2017-6865
Published May 11, 2017
Last updated 6 years ago
Overview
- Description
- A vulnerability has been identified in Primary Setup Tool (PST) (All versions < V4.2 HF1), SIMATIC Automation Tool (All versions < V3.0), SIMATIC NET PC-Software (All versions < V14 SP1), SIMATIC PCS 7 V8.1 (All versions), SIMATIC PCS 7 V8.2 (All versions < V8.2 SP1), SIMATIC STEP 7 (TIA Portal) V13 (All versions < V13 SP2), SIMATIC STEP 7 (TIA Portal) V14 (All versions < V14 SP1), SIMATIC STEP 7 V5.X (All versions < V5.6), SIMATIC WinAC RTX 2010 SP2 (All versions), SIMATIC WinAC RTX F 2010 SP2 (All versions), SIMATIC WinCC (TIA Portal) V13 (All versions < V13 SP2), SIMATIC WinCC (TIA Portal) V14 (All versions < V14 SP1), SIMATIC WinCC V7.2 and prior (All versions), SIMATIC WinCC V7.3 (All versions < V7.3 Update 15), SIMATIC WinCC V7.4 (All versions < V7.4 SP1 Upd1), SIMATIC WinCC flexible 2008 (All versions < flexible 2008 SP5), SINAUT ST7CC (All versions installed in conjunction with SIMATIC WinCC < V7.3 Update 15), SINEMA Server (All versions < V14), SINUMERIK 808D Programming Tool (All versions < V4.7 SP4 HF2), SMART PC Access (All versions < V2.3), STEP 7 - Micro/WIN SMART (All versions < V2.3), Security Configuration Tool (SCT) (All versions < V5.0). Specially crafted PROFINET DCP broadcast packets sent to the affected products on a local Ethernet segment (Layer 2) could cause a Denial-of-Service condition of some services. The services require manual restart to recover.
- Source
- productcert@siemens.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.0
- Type
- Primary
- Base score
- 6.5
- Impact score
- 3.6
- Exploitability score
- 2.8
- Vector string
- CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 6.1
- Impact score
- 6.9
- Exploitability score
- 6.5
- Vector string
- AV:A/AC:L/Au:N/C:N/I:N/A:C
Weaknesses
- nvd@nist.gov
- CWE-20
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:siemens:pcs_7:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "399B0B7B-17F7-463C-A124-5DE77337E212" }, { "criteria": "cpe:2.3:a:siemens:primary_setup_tool:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8046A64D-4C80-4199-B1A7-F77D02428ACD" }, { "criteria": "cpe:2.3:a:siemens:security_configuration_tool:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C33765E4-619E-4566-BF96-4A7C8776A0CB" }, { "criteria": "cpe:2.3:a:siemens:simatic_automation_tool:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5306C1B1-5944-49F1-8BEC-5F811C891BED" }, { "criteria": "cpe:2.3:a:siemens:simatic_net_pc-software:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6BE3E184-1158-488C-A689-34C70C6861F4" }, { "criteria": "cpe:2.3:a:siemens:simatic_step_7_\\(tia_portal\\):5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3F096B1D-366B-4E2E-A03F-607559623FE8" }, { "criteria": "cpe:2.3:a:siemens:simatic_step_7_\\(tia_portal\\):13.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "32A02189-0785-4A64-BC00-830733F21792" }, { "criteria": "cpe:2.3:a:siemens:simatic_step_7_\\(tia_portal\\):14.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "62D57BAA-A31B-4369-837D-90796779C487" }, { "criteria": "cpe:2.3:a:siemens:simatic_step_7_micro\\/win_smart:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "00CA4054-615D-4821-909A-411E4BCD3D06" }, { "criteria": "cpe:2.3:a:siemens:simatic_winac_rtx_2010:-:sp2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9D74E76A-5EE5-41AE-9C56-742EC9AD1408" }, { "criteria": "cpe:2.3:a:siemens:simatic_winac_rtx_f_2010:-:sp2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FB81FD88-3D70-4413-B035-93A3D5389170" }, { "criteria": "cpe:2.3:a:siemens:simatic_wincc:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0F7BB505-A6B6-4200-9602-E4D348E407AB" }, { "criteria": "cpe:2.3:a:siemens:simatic_wincc_\\(tia_portal\\):13.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E3D1A823-CE50-441F-B060-DA678DFE24FD" }, { "criteria": "cpe:2.3:a:siemens:simatic_wincc_\\(tia_portal\\):14.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "28A1BA01-7A92-4368-8A73-8FA47A08BC53" }, { "criteria": "cpe:2.3:a:siemens:simatic_wincc_flexible_2008:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E2429ABE-55D8-4E6D-89EB-CE016B9336ED" }, { "criteria": "cpe:2.3:a:siemens:sinaut_st7cc:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0BCB1BDC-91E7-48DC-85BA-45A2B5B840B0" }, { "criteria": "cpe:2.3:a:siemens:sinema_server:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DCC74BDB-87BD-40E1-8426-0353266F194E" }, { "criteria": "cpe:2.3:a:siemens:sinumerik_808d_programming_tool:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B82B7F7E-C9D4-4B31-9482-41BF35C8F470" }, { "criteria": "cpe:2.3:a:siemens:smart_pc_access:2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F54273D3-5C43-4343-B71F-FAD16A5CEF50" } ], "operator": "OR" } ] } ]