CVE-2017-2680
published 2017-05-11CVE-2017-2680: Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2). Human…
PriorityP424medium6.5CVSS 3.1
AVAACLPRNUINSUCNINAH
EPSS
1.15%
63.3th percentile
Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2). Human interaction is required to recover the systems. PROFIBUS interfaces are not affected.
Affected
225 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | development_evaluation_kits_for_profinet_io_dk_standard_ethernet_controller | — | — |
| siemens | development_evaluation_kits_for_profinet_io_ek-ertec_200 | — | — |
| siemens | development_evaluation_kits_for_profinet_io_ek-ertec_200p | — | — |
| siemens | dk_standard_ethernet_controller_firmware | < 4.1.1 | 4.1.1 |
| siemens | dk_standard_ethernet_controller_firmware | — | — |
| siemens | ek-ertec_200_pn_io_firmware | < 4.2.1 | 4.2.1 |
| siemens | ek-ertec_200_pn_io_firmware | — | — |
| siemens | ek-ertec_200p_pn_io_firmware | < 4.4.0 | 4.4.0 |
| siemens | ek-ertec_200p_pn_io_firmware | — | — |
| siemens | extension_unit_12_profinet | — | — |
| siemens | extension_unit_12_profinet_firmware | < 01.01.01 | 01.01.01 |
| siemens | extension_unit_15_profinet | — | — |
| siemens | extension_unit_15_profinet_firmware | < 01.01.01 | 01.01.01 |
| siemens | extension_unit_19_profinet | — | — |
| siemens | extension_unit_19_profinet_firmware | < 01.01.01 | 01.01.01 |
| siemens | extension_unit_22_profinet | — | — |
| siemens | extension_unit_22_profinet_firmware | < 01.01.01 | 01.01.01 |
| siemens | ie_as-i_link_pn_io | — | — |
| siemens | ie_pb-link | — | — |
| siemens | ie_pb-link_firmware | < 3.0 | 3.0 |
| siemens | pn_pn_coupler_firmware | < 4.0 | 4.0 |
| siemens | scalance_m-800_firmware | < 4.03 | 4.03 |
| siemens | scalance_s615_firmware | < 4.03 | 4.03 |
| siemens | scalance_w-700_ieee_802.11n_family | — | — |
| siemens | scalance_w700_firmware | < 6.1 | 6.1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.07.1HIGHCVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.06.1MEDIUMAV:A/AC:L/Au:N/C:N/I:N/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4vvg-656r-c25j: Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2)
ghsa_unreviewed·2022-05-13
CVE-2017-2680 [HIGH] CWE-400 GHSA-4vvg-656r-c25j: Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2)
Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2). Human interaction is required to recover the systems. PROFIBUS interfaces are not affected.
CISA ICS
Siemens PROFINET DCP (Update V)
cisa_ics·2021-10-14
Siemens PROFINET DCP (Update V)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens PROFINET DCP (Update V)
Last RevisedFebruary 10, 2022
Alert CodeICSA-17-129-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 6.5
- ATTENTION: Exploitable from an adjacent network/low attack complexity
- Vendor: Siemens
- Equipment: Devices using the PROFINET Discovery and Configuration Protocol (DCP)
- Vulnerabilities: Uncontrolled Resource Consumption
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the advisory update titled ICSA-17-129-02 Siemens PROFINET DCP (Update U) that was published October 14, 2021, to the ICS webpage on us-cert.cisa.gov.
## 3. RISK
CISA ICS
Siemens Medium Voltage SINAMICS Products (Update A)
cisa_ics·2018-05-10
Siemens Medium Voltage SINAMICS Products (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens Medium Voltage SINAMICS Products (Update A)
Last RevisedOctober 09, 2018
Alert CodeICSA-18-128-01
## 1. EXECUTIVE SUMMARY
-
CVSS v3 7.5
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Siemens
- Equipment: Medium Voltage SINAMICS Products
- Vulnerabilities: Improper Input Validation
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the original advisory titled ICSA-18-128-01 Siemens Medium Voltage SINAMICS Products that was published May 10, 2018, on the NCCIC/ICS-CERT website.
## 3. RISK EVALUATION
Successful exploitation of
CISA ICS
Siemens Industrial Products (Update A)
cisa_ics·2018-01-23
Siemens Industrial Products (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens Industrial Products (Update A)
Last RevisedFebruary 12, 2019
Alert CodeICSA-18-023-02
## 1. EXECUTIVE SUMMARY
-
CVSS v3 6.5
- ATTENTION: Exploitable from an adjacent network/low skill level to exploit
- Vendor: Siemens
- Equipment: Industrial Products
- Vulnerabilities: Improper Input Validation
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the original advisory titled ICSA-18-023-02 Siemens Industrial Products that was published January 23, 2018, on the NCCIC/ICS-CERT website.
## 3. RISK EVALUATION
Successful exploitation of this vulnerability
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/98369http://www.securitytracker.com/id/1038463https://cert-portal.siemens.com/productcert/html/ssa-284673.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-293562.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-546832.htmlhttps://cert-portal.siemens.com/productcert/pdf/ssa-284673.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-293562.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-546832.pdfhttps://ics-cert.us-cert.gov/advisories/ICSA-18-023-02https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-284673.pdfhttp://www.securityfocus.com/bid/98369http://www.securitytracker.com/id/1038463https://cert-portal.siemens.com/productcert/html/ssa-284673.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-293562.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-546832.htmlhttps://cert-portal.siemens.com/productcert/pdf/ssa-284673.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-293562.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-546832.pdfhttps://ics-cert.us-cert.gov/advisories/ICSA-18-023-02https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-284673.pdf
2017-05-11
Published