Siemens Simatic S7-1500 Software Controller Firmware vulnerabilities

3 known vulnerabilities affecting siemens/simatic_s7-1500_software_controller_firmware.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3

Vulnerabilities

Page 1 of 1
CVE-2023-28831HIGHCVSS 8.7fixed in 2.9.72023-09-12
CVE-2023-28831 [HIGH] CWE-190 CVE-2023-28831: The OPC UA implementations (ANSI C and C++) in affected products contain an integer overflow vulnera The OPC UA implementations (ANSI C and C++) in affected products contain an integer overflow vulnerability that could cause the application to run into an infinite loop during certificate validation. This could allow an unauthenticated remote attacker to create a denial of service condition by sending a specially crafted certificate.
nvd
CVE-2020-15796HIGHCVSS 7.5≤ 20.82020-12-14
CVE-2020-15796 [HIGH] CWE-248 CVE-2020-15796: A vulnerability has been identified in SIMATIC ET 200SP Open Controller (incl. SIPLUS variants) (V20 A vulnerability has been identified in SIMATIC ET 200SP Open Controller (incl. SIPLUS variants) (V20.8), SIMATIC S7-1500 Software Controller (V20.8). The web server of the affected products contains a vulnerability that could allow a remote attacker to trigger a denial-of-service condition by sending a specially crafted HTTP request.
nvd
CVE-2017-2680HIGHCVSS 7.1fixed in 2.12017-05-11
CVE-2017-2680 [HIGH] CWE-400 CVE-2017-2680: Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affect Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2). Human interaction is required to recover the systems. PROFIBUS interfaces are not affected.
nvd