Siemens Industrial Products LLDP Buffer Overflow (CVE-2015-8011)

critical Tenable OT Security Plugin ID 503064

Synopsis

The remote OT asset is affected by a vulnerability.

Description

Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c in lldpd before 0.8.0 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via vectors involving large management addresses and TLV boundaries.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

Refer to the vendor advisory.

See Also

https://www.cisa.gov/news-events/ics-advisories/icsa-21-194-07

https://cert-portal.siemens.com/productcert/pdf/ssa-941426.pdf

https://support.industry.siemens.com/cs/ww/en/view/109746530

https://support.industry.siemens.com/cs/ww/en/view/109798331/

https://support.industry.siemens.com/cs/ww/en/view/109811116/

https://support.industry.siemens.com/cs/ww/en/view/109812218

https://support.industry.siemens.com/cs/ww/en/view/109800773/

https://support.industry.siemens.com/cs/ww/en/view/109817067/

Plugin Details

Severity: Critical

ID: 503064

Version: 1.1

Type: remote

Family: Tenable.ot

Published: 3/13/2025

Updated: 3/13/2025

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:siemens:simatic_cp_1545-1_firmware:1.1, cpe:/o:siemens:siplus_et_200sp_cp_1543sp-1_isec_tx_rail_firmware:2.2.28, cpe:/o:siemens:siplus_s7-1200_cp_1243-1_firmware:3.3.46, cpe:/o:siemens:simatic_cp_1243-1_firmware:3.3.46, cpe:/o:siemens:simatic_cp_1542sp-1_firmware:2.2.28, cpe:/o:siemens:simatic_cp_1543-1_firmware:3.0, cpe:/o:siemens:siplus_net_cp_1543-1_firmware:3.0, cpe:/o:siemens:siplus_et_200sp_cp_1542sp-1_irc_tx_rail_firmware:2.2.28, cpe:/o:siemens:simatic_cp_1543sp-1_firmware:2.2.28, cpe:/o:siemens:simatic_cp_1542sp-1_irc_firmware:2.2.28, cpe:/o:siemens:siplus_et_200sp_cp_1543sp-1_isec_firmware:2.2.28, cpe:/o:siemens:siplus_s7-1200_cp_1243-1_rail_firmware:3.3.46, cpe:/o:siemens:simatic_cp_1243-8_irc_firmware:3.3.46

Required KB Items: Tenable.ot/Siemens

Exploit Ease: No known exploits are available

Patch Publication Date: 7/13/2021

Vulnerability Publication Date: 7/13/2021

Reference Information

CVE: CVE-2015-8011

CWE: 120, 400

ICSA: 21-194-07