Siemens S7-1200 Series PLC CPU < 4.0 Multiple DoS Vulnerabilities

high Nessus Network Monitor Plugin ID 140

Description

Siemens S7-1200 PLC central processing units (CPUs) prior to 4.0 are vulnerable to a Denial of Service (DoS) condition via specially crafted packets on port 161/udp (SNMP) and port 102/tcp (ISO_TSAP).

See Also

http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-724606.pdf

http://www.industry.siemens.com/topics/global/en/industrial-security/news-alerts/Pages/alerts.aspx

Plugin Details

Severity: High

ID: 140

Family: SCADA

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.1

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

Reference Information

CVE: CVE-2013-0700, CVE-2013-2780

BID: 5939957023