CVE-2014-2253
published 2014-03-16CVE-2014-2253: Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allow remote attackers to cause a denial of service (defect-mode transition) via crafted…
PriorityP422medium6.1CVSS 2.0
AVAACLAuNCNINAC
EPSS
1.01%
59.1th percentile
Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allow remote attackers to cause a denial of service (defect-mode transition) via crafted Profinet packets.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | simatic_s7-1500_cpu_firmware | <= 1.1.2 | — |
| siemens | simatic_s7-1500_cpu_firmware | — | — |
| siemens | simatic_s7-1500_cpu_firmware | — | — |
| siemens | simatic_s7-1500_cpu_firmware | — | — |
| siemens | simatic_s7_cpu_1200_firmware | <= 3.0.2 | — |
| siemens | simatic_s7_cpu_1200_firmware | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jmv9-4c44-h234: Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1
ghsa_unreviewed·2022-05-13
CVE-2014-2253 [MEDIUM] GHSA-jmv9-4c44-h234: Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1
Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allow remote attackers to cause a denial of service (defect-mode transition) via crafted Profinet packets.
GHSA
GHSA-5w44-54j8-r459: Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4
ghsa_unreviewed·2022-05-13·CVSS 6.1
CVE-2014-2252 [MEDIUM] GHSA-5w44-54j8-r459: Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4
Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a denial of service (defect-mode transition) via crafted PROFINET packets, a different vulnerability than CVE-2014-2253.
CISA ICS
Siemens SIMATIC S7-1500 CPU Firmware Vulnerabilities
cisa_ics·2018-09-06
Siemens SIMATIC S7-1500 CPU Firmware Vulnerabilities
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU Firmware Vulnerabilities
Last RevisedSeptember 06, 2018
Alert CodeICSA-14-073-01
## OVERVIEW
Siemens and Positive Technology researchers (Yury Goltsev, Llya Karpov, Alexey Osipov, Dmitry Serebryannikov and Alex Timorin) have identified nine firmware vulnerabilities in the Siemens SIMATIC S7-1500 CPU Firmware. Siemens has produced a patch that mitigates these vulnerabilities.
These vulnerabilities could be exploited remotely.
## AFFECTED PRODUCTS
The following SIMATIC S7-1500 versions are affected:
- SIMATIC S7-1500 CPU family, all versions older t
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://ics-cert.us-cert.gov/advisories/ICSA-14-073-01http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-456423.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-456423.pdfhttp://ics-cert.us-cert.gov/advisories/ICSA-14-073-01http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-456423.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-456423.pdf
2014-03-16
Published