CVE-2017-12741
published 2017-12-26CVE-2017-12741: Specially crafted packets sent to port 161/udp could cause a denial of service condition. The affected devices must be restarted manually.
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.31%
87.2th percentile
Specially crafted packets sent to port 161/udp could cause a denial of service condition. The affected devices must be restarted manually.
Affected
84 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | development_evaluation_kits_for_profinet_io_dk_standard_ethernet_controller | — | — |
| siemens | development_evaluation_kits_for_profinet_io_ek-ertec_200 | — | — |
| siemens | development_evaluation_kits_for_profinet_io_ek-ertec_200p | — | — |
| siemens | ek-ertec_200p_firmware | < 4.5 | 4.5 |
| siemens | simatic_compact_field_unit | — | — |
| siemens | simatic_et200ecopn_io-link_master | — | — |
| siemens | simatic_et200s | — | — |
| siemens | simatic_et_200al_im_157-1_pn | < V1.0.2 | V1.0.2 |
| siemens | simatic_et_200m | — | — |
| siemens | simatic_et_200mp_im_155-5_pn_ba | < V4.0.2 | V4.0.2 |
| siemens | simatic_et_200mp_im_155-5_pn_hf | < V4.2.0 | V4.2.0 |
| siemens | simatic_et_200mp_im_155-5_pn_st | < V4.1.0 | V4.1.0 |
| siemens | simatic_et_200pro_im_154-3_pn_hf | < * | * |
| siemens | simatic_et_200pro_im_154-4_pn_hf | < * | * |
| siemens | simatic_et_200sp_im_155-6_pn_ba | < * | * |
| siemens | simatic_et_200sp_im_155-6_pn_ha | — | — |
| siemens | simatic_et_200sp_im_155-6_pn_hf | < V4.2.0 | V4.2.0 |
| siemens | simatic_et_200sp_im_155-6_pn_hs | < V4.0.1 | V4.0.1 |
| siemens | simatic_et_200sp_im_155-6_pn_st | < * | * |
| siemens | simatic_et_200sp_im_155-6_pn_st_ba | < * | * |
| siemens | simatic_pn_pn_coupler | — | — |
| siemens | simatic_s7-1200_cpu_family | — | — |
| siemens | simatic_s7-1500_controller_firmware | — | — |
| siemens | simatic_s7-1500_cpu_family | — | — |
| siemens | simatic_s7-1500_firmware | < 2.0 | 2.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens Industrial Products (Update S)
cisa_ics·2021-06-08
Siemens Industrial Products (Update S)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens Industrial Products (Update S)
Last RevisedOctober 14, 2021
Alert CodeICSA-17-339-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Remotely exploitable/low attack complexity
- Vendor: Siemens
- Equipment: Industrial Products
- Vulnerability: Improper Input Validation
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the advisory update titled ICSA-17-339-01 Siemens Industrial Products (Update R) published June 8, 2021, to the ICS webpage on us-cert.cisa.gov.
## 3. RISK EVALUATION
Successful exploitation of this vulnerability may allow a remote
CISA ICS
Siemens SIMOCODE pro V EIP
cisa_ics·2019-04-09·CVSS 8.7
[HIGH] Siemens SIMOCODE pro V EIP
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SIMOCODE pro V EIP
Last RevisedApril 09, 2019
Alert CodeICSA-19-099-01
## 1. EXECUTIVE SUMMARY
-
CVSS v3 7.5
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Siemens
- Equipment: SIMOCODE pro V EIP
- Vulnerability: Uncontrolled Resource Consumption
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could cause a denial-of-service condition.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of SIMOCODE pro V EIP, a motor management system for low-voltage motors, are affected:
- SIMOCODE pro V EIP all v
CISA ICS
Siemens Medium Voltage SINAMICS Products (Update A)
cisa_ics·2018-05-10
Siemens Medium Voltage SINAMICS Products (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens Medium Voltage SINAMICS Products (Update A)
Last RevisedOctober 09, 2018
Alert CodeICSA-18-128-01
## 1. EXECUTIVE SUMMARY
-
CVSS v3 7.5
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Siemens
- Equipment: Medium Voltage SINAMICS Products
- Vulnerabilities: Improper Input Validation
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the original advisory titled ICSA-18-128-01 Siemens Medium Voltage SINAMICS Products that was published May 10, 2018, on the NCCIC/ICS-CERT website.
## 3. RISK EVALUATION
Successful exploitation of
GHSA
GHSA-89jc-9q2j-97hr: A vulnerability has been identified in Development/Evaluation Kits for PROFINET IO: DK Standard Ethernet Controller, Development/Evaluation Kits for P
ghsa_unreviewed·2022-05-13
CVE-2017-12741 [HIGH] CWE-400 GHSA-89jc-9q2j-97hr: A vulnerability has been identified in Development/Evaluation Kits for PROFINET IO: DK Standard Ethernet Controller, Development/Evaluation Kits for P
A vulnerability has been identified in Development/Evaluation Kits for PROFINET IO: DK Standard Ethernet Controller, Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200, Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200P, SIMATIC Compact Field Unit, SIMATIC ET200AL, SIMATIC ET200M (incl. SIPLUS variants), SIMATIC ET200MP IM155-5 PN BA (incl. SIPLUS variants), SIMATIC ET200MP IM155-5 PN HF (incl. SIPLUS variants), SIMATIC ET200MP IM155-5 PN ST (incl. SIPLUS variants), SIMATIC ET200S (incl. SIPLUS variants), SIMATIC ET200SP IM155-6 PN BA (incl. SIPLUS variants), SIMATIC ET200SP IM155-6 PN HA (incl. SIPLUS variants), SIMATIC ET200SP IM155-6 PN HF (incl. SIPLUS variants), SIMATIC ET200SP IM155-6 PN HS (incl. SIPLUS variants), SIMATIC ET200SP IM155-6 PN ST (incl. SIPLUS variants),
No detection rules found.
No public exploits indexed.
https://cert-portal.siemens.com/productcert/html/ssa-141614.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-346262.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-546832.htmlhttps://cert-portal.siemens.com/productcert/pdf/ssa-141614.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-346262.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-546832.pdfhttps://www.securityfocus.com/bid/101964https://cert-portal.siemens.com/productcert/html/ssa-141614.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-346262.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-546832.htmlhttps://cert-portal.siemens.com/productcert/pdf/ssa-141614.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-346262.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-546832.pdfhttps://www.securityfocus.com/bid/101964
2017-12-26
Published