cvelist/2017/2xxx/CVE-2017-2680.json

310 lines
19 KiB
JSON
Raw Normal View History

2017-10-16 12:31:07 -04:00
{
"CVE_data_meta" : {
"ASSIGNER" : "productcert@siemens.com",
"ID" : "CVE-2017-2680",
"STATE" : "PUBLIC"
},
"affects" : {
"vendor" : {
"vendor_data" : [
{
"product" : {
"product_data" : [
{
"product_name" : "Development/Evaluation Kit DK Standard Ethernet Controller, Development/Evaluation Kit EK-ERTEC 200 PN IO, Development/Evaluation Kit EK-ERTEC 200P PN IO, IE/AS-i Link PN IO, IE/PB-Link, SCALANCE M-800, S615, SCALANCE W700, SCALANCE X-200, SCALANCE X-200 IRT, SCALANCE X-300/X408, SCALANCE X414, SCALANCE XM400, SCALANCE XR500, SIMATIC WinAC RTX 2010 incl. F, SIMATIC CM 1542-1, SIMATIC CM 1542SP-1, SIMATIC CP 1243-1, SIMATIC CP 1243-1 DNP3, SIMATIC CP 1243-1 IEC, SIMATIC CP 1243-1 IRC, SIMATIC CP 1542SP-1 IRC, SIMATIC CP 1543-1, SIMATIC CP 1543SP-1, SIMATIC CP 1604, SIMATIC CP 1616, SIMATIC CP 343-1 Adv, SIMATIC CP 343-1 Lean, SIMATIC CP 343-1 Std, SIMATIC CP 443-1 Adv, SIMATIC CP 443-1 OPC-UA, SIMATIC CP 443-1 Std, SIMATIC DK-16xx PN IO, SIMATIC ET 200AL, SIMATIC ET 200M, SIMATIC ET 200MP, SIMATIC ET 200S, SIMATIC ET 200SP, SIMATIC ET 200ecoPN, SIMATIC ET 200pro, SIMATIC HMI Comfort Panels, HMI Multi Panels, HMI Mobile Panels, SIMATIC PN/PN Coupler, SIMATIC RF650R, SIMATIC RF680R, SIMATIC RF685R, SIMATIC S7-1200 incl. F, SIMATIC S7-1500 Software Controller incl. F, SIMATIC S7-1500 incl. F, T, and TF, SIMATIC S7-200 SMART, SIMATIC S7-300 incl. F and T, SIMATIC S7-400 PN/DP V6 Incl. F, SIMATIC S7-400 PN/DP V7 Incl. F, SIMATIC S7-400-H V6, SIMATIC S7-410, SIMATIC Teleservice Adapter Standard Modem, IE Basic, IE Advanced, SIMOCODE pro V PROFINET, SIMOTION, SINAMICS DCM w. PN, SINAMICS DCP w. PN, SINAMICS G110M w. PN, SINAMICS G120(C/P/D) w. PN, SINAMICS G130 V4.7 w. PN, SINAMICS G130 V4.8 w. PN, SINAMICS G150 V4.7 w. PN, SINAMICS G150 V4.8 w. PN, SINAMICS S110 w. PN, SINAMICS S120 V4.7 w. PN, SINAMICS S120 V4.8 w. PN, SINAMICS S150 V4.7 w. PN, SINAMICS S150 V4.8 w. PN, SINAMICS V90 w. PN, SINUMERIK 828D V4.5 and prior, SINUMERIK 828D V4.7, SINUMERIK 840D sl V4.5 and prior, SINUMERIK 840D sl V4.7, SIRIUS ACT 3SU1 interface module PROFINET, SIRIUS Motor Starter M200D PROFINET, SIRIUS Soft Starter 3RW44 PN, SITOP PSU8600 PROFINET, SITOP UPS1600 PROFINET, Softnet PROFINET IO for PC-based Windows systems",
2017-10-16 12:31:07 -04:00
"version" : {
"version_data" : [
{
"version_value" : "Development/Evaluation Kit DK Standard Ethernet Controller : All versions < V4.1.1 Patch04"
},
{
"version_value" : "Development/Evaluation Kit EK-ERTEC 200 PN IO : All versions < V4.2.1 Patch03"
},
{
"version_value" : "Development/Evaluation Kit EK-ERTEC 200P PN IO : All versions < V4.4. Patch01"
},
{
"version_value" : "IE/AS-i Link PN IO : All versions"
},
{
"version_value" : "IE/PB-Link : All versions < V3.0"
},
{
"version_value" : "SCALANCE M-800, S615 : All versions < V4.03"
},
{
"version_value" : "SCALANCE W700 : All versions < V6.1"
},
{
"version_value" : "SCALANCE X-200 : All versions < V5.2.2"
},
{
"version_value" : "SCALANCE X-200 IRT : All versions"
},
{
"version_value" : "SCALANCE X-300/X408 : All versions < V4.1.0"
},
{
"version_value" : "SCALANCE X414 : All versions < V3.10.2"
},
{
"version_value" : "SCALANCE XM400 : All versions < V6.1"
},
{
"version_value" : "SCALANCE XR500 : All versions < V6.1"
},
{
"version_value" : "SIMATIC WinAC RTX 2010 incl. F : All versions"
},
{
"version_value" : "SIMATIC CM 1542-1 : All versions < V2.0"
},
{
"version_value" : "SIMATIC CM 1542SP-1 : All versions < V1.0.15"
},
{
"version_value" : "SIMATIC CP 1243-1 : All versions < V2.1.82"
},
{
"version_value" : "SIMATIC CP 1243-1 DNP3 : All versions"
},
{
"version_value" : "SIMATIC CP 1243-1 IEC : All versions"
},
{
"version_value" : "SIMATIC CP 1243-1 IRC : All versions < V2.1.82"
},
{
"version_value" : "SIMATIC CP 1542SP-1 IRC : All versions < V1.0.15"
},
{
"version_value" : "SIMATIC CP 1543-1 : All versions < V2.1"
},
{
"version_value" : "SIMATIC CP 1543SP-1 : All versions < V1.0.15"
},
{
"version_value" : "SIMATIC CP 1604 : All versions < V2.7"
},
{
"version_value" : "SIMATIC CP 1616 : All versions < V2.7"
},
{
"version_value" : "SIMATIC CP 343-1 Adv : All versions"
},
{
"version_value" : "SIMATIC CP 343-1 Lean : All versions"
},
{
"version_value" : "SIMATIC CP 343-1 Std : All versions"
},
{
"version_value" : "SIMATIC CP 443-1 Adv : All versions < V3.2.17"
},
{
"version_value" : "SIMATIC CP 443-1 OPC-UA : All versions"
},
{
"version_value" : "SIMATIC CP 443-1 Std : All versions < V3.2.17"
},
{
"version_value" : "SIMATIC DK-16xx PN IO : All versions < V2.7"
},
{
"version_value" : "SIMATIC ET 200AL : All versions < V1.0.2"
},
{
"version_value" : "SIMATIC ET 200M : All versions"
},
{
"version_value" : "SIMATIC ET 200MP : All versions < V4.0.1"
},
{
"version_value" : "SIMATIC ET 200S : All versions"
},
{
"version_value" : "SIMATIC ET 200SP : All versions < V4.1.0"
},
{
"version_value" : "SIMATIC ET 200ecoPN : All versions"
},
{
"version_value" : "SIMATIC ET 200pro : All versions"
},
{
"version_value" : "SIMATIC HMI Comfort Panels, HMI Multi Panels, HMI Mobile Panels : All versions"
},
{
"version_value" : "SIMATIC PN/PN Coupler : All versions < V4.0"
},
{
"version_value" : "SIMATIC RF650R : All versions < V3.0"
},
{
"version_value" : "SIMATIC RF680R : All versions < V3.0"
},
{
"version_value" : "SIMATIC RF685R : All versions < V3.0"
},
{
"version_value" : "SIMATIC S7-1200 incl. F : All versions < V4.2.1"
},
{
"version_value" : "SIMATIC S7-1500 Software Controller incl. F : All versions < V2.1"
},
{
"version_value" : "SIMATIC S7-1500 incl. F, T, and TF : All versions < V2.1"
},
{
"version_value" : "SIMATIC S7-200 SMART : All versions < V2.3"
},
{
"version_value" : "SIMATIC S7-300 incl. F and T : All versions < V3.X.14"
},
{
"version_value" : "SIMATIC S7-400 PN/DP V6 Incl. F : All versions < V6.0.6"
},
{
"version_value" : "SIMATIC S7-400 PN/DP V7 Incl. F : All versions < V7.0.2"
},
{
"version_value" : "SIMATIC S7-400-H V6 : All versions < V6.0.7"
},
{
"version_value" : "SIMATIC S7-410 : All versions < V8.2"
},
{
"version_value" : "SIMATIC Teleservice Adapter Standard Modem, IE Basic, IE Advanced : All versions"
},
{
"version_value" : "SIMOCODE pro V PROFINET : All versions < V2.0.0"
},
{
"version_value" : "SIMOTION : All versions < V4.5 HF1"
},
{
"version_value" : "SINAMICS DCM w. PN : All versions < V1.4 SP1 HF5"
},
{
"version_value" : "SINAMICS DCP w. PN : All versions < V1.2 HF 1"
},
{
"version_value" : "SINAMICS G110M w. PN : All versions < V4.7 SP6 HF3"
},
{
"version_value" : "SINAMICS G120(C/P/D) w. PN : All versions < V4.7 SP6 HF3"
},
{
"version_value" : "SINAMICS G130 V4.7 w. PN : All versions < V4.7 HF27"
},
{
"version_value" : "SINAMICS G130 V4.8 w. PN : All versions < V4.8 HF4"
},
{
"version_value" : "SINAMICS G150 V4.7 w. PN : V4.7: All versions < V4.7 HF27"
},
{
"version_value" : "SINAMICS G150 V4.8 w. PN : All versions < V4.8 HF4"
},
{
"version_value" : "SINAMICS S110 w. PN : All versions < V4.4 SP3 HF5"
},
{
"version_value" : "SINAMICS S120 V4.7 w. PN : All versions < V4.7 HF27"
},
{
"version_value" : "SINAMICS S120 V4.8 w. PN : All versions < V4.8 HF4"
},
{
"version_value" : "SINAMICS S150 V4.7 w. PN : All versions < V4.7 HF27"
},
{
"version_value" : "SINAMICS S150 V4.8 w. PN : All versions < V4.8 HF4"
},
{
"version_value" : "SINAMICS V90 w. PN : All versions < V1.01"
},
{
"version_value" : "SINUMERIK 828D V4.5 and prior : All versions < V4.5 SP6 HF2"
},
{
"version_value" : "SINUMERIK 828D V4.7 : All versions < V4.7 SP4 HF1"
},
{
"version_value" : "SINUMERIK 840D sl V4.5 and prior : All versions < V4.5 SP6 HF2"
},
{
"version_value" : "SINUMERIK 840D sl V4.7 : All versions < V4.7 SP4 HF1"
},
{
"version_value" : "SIRIUS ACT 3SU1 interface module PROFINET : All versions"
},
{
"version_value" : "SIRIUS Motor Starter M200D PROFINET : All versions"
},
{
"version_value" : "SIRIUS Soft Starter 3RW44 PN : All versions"
},
{
"version_value" : "SITOP PSU8600 PROFINET : All versions < V1.2.0"
},
{
"version_value" : "SITOP UPS1600 PROFINET : All versions < V2.2.0"
},
{
"version_value" : "Softnet PROFINET IO for PC-based Windows systems : All versions < V14 SP1"
2017-10-16 12:31:07 -04:00
}
]
}
}
]
},
"vendor_name" : "Siemens AG"
2017-10-16 12:31:07 -04:00
}
]
}
},
"data_format" : "MITRE",
"data_type" : "CVE",
"data_version" : "4.0",
"description" : {
"description_data" : [
{
"lang" : "eng",
"value" : "A vulnerability has been identified in Development/Evaluation Kit DK Standard Ethernet Controller, Development/Evaluation Kit EK-ERTEC 200 PN IO, Development/Evaluation Kit EK-ERTEC 200P PN IO, IE/AS-i Link PN IO, IE/PB-Link, SCALANCE M-800, S615, SCALANCE W700, SCALANCE X-200, SCALANCE X-200 IRT, SCALANCE X-300/X408, SCALANCE X414, SCALANCE XM400, SCALANCE XR500, SIMATIC WinAC RTX 2010 incl. F, SIMATIC CM 1542-1, SIMATIC CM 1542SP-1, SIMATIC CP 1243-1, SIMATIC CP 1243-1 DNP3, SIMATIC CP 1243-1 IEC, SIMATIC CP 1243-1 IRC, SIMATIC CP 1542SP-1 IRC, SIMATIC CP 1543-1, SIMATIC CP 1543SP-1, SIMATIC CP 1604, SIMATIC CP 1616, SIMATIC CP 343-1 Adv, SIMATIC CP 343-1 Lean, SIMATIC CP 343-1 Std, SIMATIC CP 443-1 Adv, SIMATIC CP 443-1 OPC-UA, SIMATIC CP 443-1 Std, SIMATIC DK-16xx PN IO, SIMATIC ET 200AL, SIMATIC ET 200M, SIMATIC ET 200MP, SIMATIC ET 200S, SIMATIC ET 200SP, SIMATIC ET 200ecoPN, SIMATIC ET 200pro, SIMATIC HMI Comfort Panels, HMI Multi Panels, HMI Mobile Panels, SIMATIC PN/PN Coupler, SIMATIC RF650R, SIMATIC RF680R, SIMATIC RF685R, SIMATIC S7-1200 incl. F, SIMATIC S7-1500 Software Controller incl. F, SIMATIC S7-1500 incl. F, T, and TF, SIMATIC S7-200 SMART, SIMATIC S7-300 incl. F and T, SIMATIC S7-400 PN/DP V6 Incl. F, SIMATIC S7-400 PN/DP V7 Incl. F, SIMATIC S7-400-H V6, SIMATIC S7-410, SIMATIC Teleservice Adapter Standard Modem, IE Basic, IE Advanced, SIMOCODE pro V PROFINET, SIMOTION, SINAMICS DCM w. PN, SINAMICS DCP w. PN, SINAMICS G110M w. PN, SINAMICS G120(C/P/D) w. PN, SINAMICS G130 V4.7 w. PN, SINAMICS G130 V4.8 w. PN, SINAMICS G150 V4.7 w. PN, SINAMICS G150 V4.8 w. PN, SINAMICS S110 w. PN, SINAMICS S120 V4.7 w. PN, SINAMICS S120 V4.8 w. PN, SINAMICS S150 V4.7 w. PN, SINAMICS S150 V4.8 w. PN, SINAMICS V90 w. PN, SINUMERIK 828D V4.5 and prior, SINUMERIK 828D V4.7, SINUMERIK 840D sl V4.5 and prior, SINUMERIK 840D sl V4.7, SIRIUS ACT 3SU1 interface module PROFINET, SIRIUS Motor Starter M200D PROFINET, SIRIUS Soft Starter 3RW44 PN, SITOP PSU8600 PROFINET, SITOP UPS1600 PROFINET, Softnet PROFINET IO for PC-based Windows systems. Specially crafted PROFINET DCP broadcast packets could cause a Denial-of-Service condition of affected products on a local Ethernet segment (Layer 2). Human interaction is required to recover the systems. PROFIBUS interfaces are not affected."
2017-10-16 12:31:07 -04:00
}
]
},
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng",
"value" : "CWE-20: Improper Input Validation"
}
]
}
]
},
"references" : {
"reference_data" : [
2018-01-25 01:02:17 -05:00
{
"url" : "https://ics-cert.us-cert.gov/advisories/ICSA-18-023-02"
},
{
2018-01-18 15:04:24 -05:00
"url" : "https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-293562.pdf"
2018-01-24 11:02:41 -05:00
},
{
"url" : "https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-284673.pdf"
},
{
"url" : "http://www.securityfocus.com/bid/98369"
},
{
"url" : "http://www.securitytracker.com/id/1038463"
2017-10-16 12:31:07 -04:00
}
]
}
}