CVE-2021-37185
published 2022-02-09CVE-2021-37185: A vulnerability has been identified in SIMATIC Drive Controller family (All versions >= V2.9.2 = V21.9 = V4.5.0 = V2.9.2 = V21.9 = V4.0 < V4.0 SP1), SIPLUS TIM…
PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.06%
79.2th percentile
A vulnerability has been identified in SIMATIC Drive Controller family (All versions >= V2.9.2 = V21.9 = V4.5.0 = V2.9.2 = V21.9 = V4.0 < V4.0 SP1), SIPLUS TIM 1531 IRC (All versions < V2.3.6), TIM 1531 IRC (All versions < V2.3.6). An unauthenticated attacker could cause a denial-of-service condition in a PLC when sending specially prepared packets over port 102/tcp. A restart of the affected device is needed to restore normal operations.
Affected
55 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | simatic_drive_controller_cpu_1504d_tf_firmware | < 2.9.4 | 2.9.4 |
| siemens | simatic_drive_controller_cpu_1507d_tf_firmware | < 2.9.4 | 2.9.4 |
| siemens | simatic_drive_controller_family | — | — |
| siemens | simatic_et_200sp_open_controller_cpu_1515sp_pc2 | — | — |
| siemens | simatic_s7-1200_cpu_1211c_firmware | >= 4.5.0 < 4.5.2 | 4.5.2 |
| siemens | simatic_s7-1200_cpu_1212c_firmware | >= 4.5.0 < 4.5.2 | 4.5.2 |
| siemens | simatic_s7-1200_cpu_1212fc_firmware | >= 4.5.0 < 4.5.2 | 4.5.2 |
| siemens | simatic_s7-1200_cpu_1214c_firmware | >= 4.5.0 < 4.5.2 | 4.5.2 |
| siemens | simatic_s7-1200_cpu_1214fc_firmware | >= 4.5.0 < 4.5.2 | 4.5.2 |
| siemens | simatic_s7-1200_cpu_1215c_firmware | >= 4.5.0 < 4.5.2 | 4.5.2 |
| siemens | simatic_s7-1200_cpu_1215fc_firmware | >= 4.5.0 < 4.5.2 | 4.5.2 |
| siemens | simatic_s7-1200_cpu_1217c_firmware | >= 4.5.0 < 4.5.2 | 4.5.2 |
| siemens | simatic_s7-1200_cpu_family | — | — |
| siemens | simatic_s7-1500_cpu_1510sp-1_firmware | >= 2.9.2 < 2.9.4 | 2.9.4 |
| siemens | simatic_s7-1500_cpu_1510sp_firmware | >= 2.9.2 < 2.9.4 | 2.9.4 |
| siemens | simatic_s7-1500_cpu_1511-1_firmware | >= 2.9.2 < 2.9.4 | 2.9.4 |
| siemens | simatic_s7-1500_cpu_1511c-1_firmware | >= 2.9.2 < 2.9.4 | 2.9.4 |
| siemens | simatic_s7-1500_cpu_1511f-1_firmware | >= 2.9.2 < 2.9.4 | 2.9.4 |
| siemens | simatic_s7-1500_cpu_1511t-1_firmware | >= 2.9.2 < 2.9.4 | 2.9.4 |
| siemens | simatic_s7-1500_cpu_1511tf-1_firmware | >= 2.9.2 < 2.9.4 | 2.9.4 |
| siemens | simatic_s7-1500_cpu_1512c-1_firmware | >= 2.9.2 < 2.9.4 | 2.9.4 |
| siemens | simatic_s7-1500_cpu_1512sp-1_firmware | >= 2.9.2 < 2.9.4 | 2.9.4 |
| siemens | simatic_s7-1500_cpu_1512spf-1_firmware | >= 2.9.2 < 2.9.4 | 2.9.4 |
| siemens | simatic_s7-1500_cpu_1513-1_firmware | >= 2.9.2 < 2.9.4 | 2.9.4 |
| siemens | simatic_s7-1500_cpu_1513f-1_firmware | >= 2.9.2 < 2.9.4 | 2.9.4 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pwf7-gchp-6gf8: A vulnerability has been identified in SIMATIC Drive Controller family (All versions = V4
ghsa_unreviewed·2022-02-10
CVE-2021-37185 [HIGH] CWE-672 GHSA-pwf7-gchp-6gf8: A vulnerability has been identified in SIMATIC Drive Controller family (All versions = V4
A vulnerability has been identified in SIMATIC Drive Controller family (All versions = V4.5.0 = V2.9.2 = V2.2). An unauthenticated attacker could cause a denial-of-service condition in a PLC when sending specially prepared packets over port 102/tcp. A restart of the affected device is needed to restore normal operations.
CISA ICS
Siemens SIMATIC Industrial Products (Update B)
cisa_ics·2022-02-10
Siemens SIMATIC Industrial Products (Update B)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SIMATIC Industrial Products (Update B)
Last RevisedJuly 14, 2022
Alert CodeICSA-22-041-01
## As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: Siemens SIMATIC Industrial Products
- V
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-02-09
Published