CVE-2018-16559Improper Input Validation in Siemens Simatic S7-1500 Firmware

Severity
7.5HIGHNVD
EPSS
1.1%
top 21.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 17
Latest updateMay 14

Description

A vulnerability has been identified in SIMATIC S7-1500 CPU (All versions >= V2.0 and < V2.5), SIMATIC S7-1500 CPU (All versions <= V1.8.5). Specially crafted network packets sent to port 80/tcp or 443/tcp could allow an unauthenticated remote attacker to cause a Denial-of-Service condition of the device. The security vulnerability could be exploited by an attacker with network access to the affected systems on port 80/tcp or 443/tcp. Successful exploitation requires no system privileges and no u

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

CVEListV5siemens/simatic_s7-1500_cpuAll versions <= V1.8.5, All versions >= V2.0 and < V2.5+1

🔴Vulnerability Details

2
GHSA
GHSA-f6v4-p9wf-p829: A vulnerability has been identified in SIMATIC S7-1500 CPU (All versions >= V22022-05-14
CVEList
CVE-2018-16559: A vulnerability has been identified in SIMATIC S7-1500 CPU (All versions >= V22019-04-17
CVE-2018-16559 — Improper Input Validation in Siemens | cvebase