mirror of
https://github.com/CVEProject/cvelist.git
synced 2025-07-29 05:56:59 +00:00
275 lines
18 KiB
JSON
275 lines
18 KiB
JSON
{
|
|
"CVE_data_meta" : {
|
|
"ASSIGNER" : "productcert@siemens.com",
|
|
"DATE_PUBLIC" : "2017-05-08T00:00:00",
|
|
"ID" : "CVE-2017-2680",
|
|
"STATE" : "PUBLIC"
|
|
},
|
|
"affects" : {
|
|
"vendor" : {
|
|
"vendor_data" : [
|
|
{
|
|
"product" : {
|
|
"product_data" : [
|
|
{
|
|
"product_name" : "SIEMENS SIMATIC CP 343-1 Std, CP 343-1 Lean, SIMATIC CP 343-1 Adv, SIMATIC CP 443-1 Std, CP 443-1 Adv, SIMATIC CP 443-1 OPC-UA, SIMATIC CP 1243-1, SIMATIC CP 1243-1 IRC, SIMATIC CP 1243-1 IEC, SIMATIC CP 1243-1 DNP3, SIMATIC CM 1542-1, SIMATIC CP 1542SP-1, CP 1542SP-1 IRC, and CP 1543SP-1, SIMATIC CP 1543-1, SIMATIC RF650R, RF680R, RF685R, SIMATIC CP 1616, CP 1604, DK-16xx PN IO, SCALANCE X-200, SCALANCE X200 IRT, SCALANCE X-300/X408, SCALANCE X414, SCALANCE XM400, XR500, SCALANCE W700, SCALANCE M-800, S615, Softnet PROFINET IO for PC-based Windows systems, IE/PB-Link, IE/AS-i Link PN IO, SIMATIC Teleservice Adapter Standard Modem, IE Basic, IE Advanced, SITOP PSU8600 PROFINET, SITOP UPS1600 PROFINET, SIMATIC ET 200AL, SIMATIC ET 200ecoPN, SIMATIC ET 200M, SIMATIC ET 200MP, SIMATIC ET 200pro, SIMATIC ET 200S, SIMATIC ET 200SP, SIMATIC PN/PN Coupler, DK Standard Ethernet Controller, EK-ERTEC 200P PN IO, EK-ERTEC 200 PN IO, SIMATIC S7-200 SMART, SIMATIC S7-300 incl. F and T, SIMATIC S7-400 PN/DP V6 Incl. F, SIMATIC S7-400-H V6, SIMATIC S7-400 PN/DP V7 incl. F, SIMATIC S7-CPU 410, SIMATIC S7-1200 incl. F, SIMATIC S7-1500 incl. F, T, and TF, SIMATIC S7-1500 Software Controller incl. F, SIMATIC WinAC RTX 2010 incl. F, SIRIUS ACT 3SU1 interface module PROFINET, SIRIUS Soft starter 3RW44 PN, SIRIUS Motor starter M200D PROFINET, SIMOCODE pro V PROFINET, SINAMICS DCM, SINAMICS DCP, SINAMICS G110M / G120(C/P/D) w. PN, SINAMICS G130 and G150, SINAMICS S110 w. PN, SINAMICS S120, SINAMICS S150, SINAMICS V90 w. PN, SIMOTION, SINUMERIK 828D, SINUMERIK 840D sl, SIMATIC HMI Comfort Panels, HMI Multi Panels, HMI Mobile Panels",
|
|
"version" : {
|
|
"version_data" : [
|
|
{
|
|
"version_value" : "SIMATIC CP 343-1 Std, CP 343-1 Lean (All versions)"
|
|
},
|
|
{
|
|
"version_value" : "SIMATIC CP 343-1 Adv (All versions)"
|
|
},
|
|
{
|
|
"version_value" : "SIMATIC CP 443-1 Std, CP 443-1 Adv (All versions before V3.2.17)"
|
|
},
|
|
{
|
|
"version_value" : "SIMATIC CP 443-1 OPC-UA (All versions)"
|
|
},
|
|
{
|
|
"version_value" : "SIMATIC CP 1243-1 (All versions before V2.1.82)"
|
|
},
|
|
{
|
|
"version_value" : "SIMATIC CP 1243-1 IRC (All versions before V2.1.82)"
|
|
},
|
|
{
|
|
"version_value" : "SIMATIC CP 1243-1 IEC (All versions)"
|
|
},
|
|
{
|
|
"version_value" : "SIMATIC CP 1243-1 DNP3 (All versions)"
|
|
},
|
|
{
|
|
"version_value" : "SIMATIC CM 1542-1 (All versions before V2.0)"
|
|
},
|
|
{
|
|
"version_value" : "SIMATIC CP 1542SP-1, CP 1542SP-1 IRC, and CP 1543SP-1 (All versions before to V1.0.15)"
|
|
},
|
|
{
|
|
"version_value" : "SIMATIC CP 1543-1 (All versions before V2.1)"
|
|
},
|
|
{
|
|
"version_value" : "SIMATIC RF650R, RF680R, RF685R (All versions before V3.0)"
|
|
},
|
|
{
|
|
"version_value" : "SIMATIC CP 1616, CP 1604, DK-16xx PN IO (All versions before V2.7)"
|
|
},
|
|
{
|
|
"version_value" : "SCALANCE X-200 (All versions before V5.2.2)"
|
|
},
|
|
{
|
|
"version_value" : "SCALANCE X200 IRT (All versions before V5.4.0)"
|
|
},
|
|
{
|
|
"version_value" : "SCALANCE X-300/X408 (All versions before V4.1.0)"
|
|
},
|
|
{
|
|
"version_value" : "SCALANCE X414 (All versions before V3.10.2)"
|
|
},
|
|
{
|
|
"version_value" : "SCALANCE XM400, XR500 (All versions before V6.1)"
|
|
},
|
|
{
|
|
"version_value" : "SCALANCE W700 (All versions before V6.1)"
|
|
},
|
|
{
|
|
"version_value" : "SCALANCE M-800, S615 (All versions before V04.03)"
|
|
},
|
|
{
|
|
"version_value" : "Softnet PROFINET IO for PC-based Windows systems (All versions before V14 SP1)"
|
|
},
|
|
{
|
|
"version_value" : "IE/PB-Link (All versions before V3.0)"
|
|
},
|
|
{
|
|
"version_value" : "IE/AS-i Link PN IO (All versions)"
|
|
},
|
|
{
|
|
"version_value" : "SIMATIC Teleservice Adapter Standard Modem, IE Basic, IE Advanced (All versions)"
|
|
},
|
|
{
|
|
"version_value" : "SITOP PSU8600 PROFINET (All versions before V1.2.0)"
|
|
},
|
|
{
|
|
"version_value" : "SITOP UPS1600 PROFINET (All versions before V2.2.0)"
|
|
},
|
|
{
|
|
"version_value" : "SIMATIC ET 200AL (All versions before V1.0.2)"
|
|
},
|
|
{
|
|
"version_value" : "SIMATIC ET 200ecoPN (All versions)"
|
|
},
|
|
{
|
|
"version_value" : "SIMATIC ET 200M (All versions)"
|
|
},
|
|
{
|
|
"version_value" : "SIMATIC ET 200MP (All versions before V4.0.1)"
|
|
},
|
|
{
|
|
"version_value" : "SIMATIC ET 200pro (All versions)"
|
|
},
|
|
{
|
|
"version_value" : "SIMATIC ET 200S (All versions)"
|
|
},
|
|
{
|
|
"version_value" : "SIMATIC ET 200SP (All versions before V4.1.0)"
|
|
},
|
|
{
|
|
"version_value" : "SIMATIC PN/PN Coupler (All versions before V4.0)"
|
|
},
|
|
{
|
|
"version_value" : "DK Standard Ethernet Controller (All versions before V4.1.1 Patch04)"
|
|
},
|
|
{
|
|
"version_value" : "EK-ERTEC 200P PN IO (All versions before V4.4.0 Patch01)"
|
|
},
|
|
{
|
|
"version_value" : "EK-ERTEC 200 PN IO (All versions before V4.2.1 Patch03)"
|
|
},
|
|
{
|
|
"version_value" : "SIMATIC S7-200 SMART (All versions before V2.3)"
|
|
},
|
|
{
|
|
"version_value" : "SIMATIC S7-300 incl. F and T (All versions before V3.X.14)"
|
|
},
|
|
{
|
|
"version_value" : "SIMATIC S7-400 PN/DP V6 Incl. F (All versions before V6.0.6)"
|
|
},
|
|
{
|
|
"version_value" : "SIMATIC S7-400-H V6 (All versions before V6.0.7)"
|
|
},
|
|
{
|
|
"version_value" : "SIMATIC S7-400 PN/DP V7 incl. F (All versions)"
|
|
},
|
|
{
|
|
"version_value" : "SIMATIC S7-CPU 410 (All versions before V8.2)"
|
|
},
|
|
{
|
|
"version_value" : "SIMATIC S7-1200 incl. F (All versions before V4.2.1)"
|
|
},
|
|
{
|
|
"version_value" : "SIMATIC S7-1500 incl. F, T, and TF (All versions before V2.1)"
|
|
},
|
|
{
|
|
"version_value" : "SIMATIC S7-1500 Software Controller incl. F (All versions before V2.1)"
|
|
},
|
|
{
|
|
"version_value" : "SIMATIC WinAC RTX 2010 incl. F (All versions)"
|
|
},
|
|
{
|
|
"version_value" : "SIRIUS ACT 3SU1 interface module PROFINET (All versions)"
|
|
},
|
|
{
|
|
"version_value" : "SIRIUS Soft starter 3RW44 PN (All versions)"
|
|
},
|
|
{
|
|
"version_value" : "SIRIUS Motor starter M200D PROFINET (All versions)"
|
|
},
|
|
{
|
|
"version_value" : "SIMOCODE pro V PROFINET (All versions)"
|
|
},
|
|
{
|
|
"version_value" : "SINAMICS DCM (All versions before V1.4 SP1 HF5)"
|
|
},
|
|
{
|
|
"version_value" : "SINAMICS DCP (All versions)"
|
|
},
|
|
{
|
|
"version_value" : "SINAMICS G110M / G120(C/P/D) w. PN (All versions before V4.7 SP6 HF3)"
|
|
},
|
|
{
|
|
"version_value" : "SINAMICS G130 and G150 (All versions before V4.7 HF27 and V4.8 before HF4)"
|
|
},
|
|
{
|
|
"version_value" : "SINAMICS S110 w. PN (All versions before V4.4 SP1 HF5)"
|
|
},
|
|
{
|
|
"version_value" : "SINAMICS S120 (All versions before V4.7 HF27 and V4.8 before HF4)"
|
|
},
|
|
{
|
|
"version_value" : "SINAMICS S150 (All versions before V4.7 HF27 and V4.8 before HF4)"
|
|
},
|
|
{
|
|
"version_value" : "SINAMICS V90 w. PN (All versions before V1.1)"
|
|
},
|
|
{
|
|
"version_value" : "SIMOTION (All versions before V4.5 HF1)"
|
|
},
|
|
{
|
|
"version_value" : "SINUMERIK 828D (All versions before V4.5 SP6 HF2 and V4.7 before SP6 HF8)"
|
|
},
|
|
{
|
|
"version_value" : "SINUMERIK 840D sl (All versions before V4.5 SP6 HF8 and V4.7 before SP4 HF1)"
|
|
},
|
|
{
|
|
"version_value" : "SIMATIC HMI Comfort Panels, HMI Multi Panels, HMI Mobile Panels (All versions)."
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
},
|
|
"vendor_name" : "Siemens AG"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
"data_format" : "MITRE",
|
|
"data_type" : "CVE",
|
|
"data_version" : "4.0",
|
|
"description" : {
|
|
"description_data" : [
|
|
{
|
|
"lang" : "eng",
|
|
"value" : "SIEMENS SIMATIC CP 343-1 Std, CP 343-1 Lean (All versions), SIMATIC CP 343-1 Adv (All versions), SIMATIC CP 443-1 Std, CP 443-1 Adv (All versions before V3.2.17), SIMATIC CP 443-1 OPC-UA (All versions), SIMATIC CP 1243-1 (All versions before V2.1.82), SIMATIC CP 1243-1 IRC (All versions before V2.1.82), SIMATIC CP 1243-1 IEC (All versions), SIMATIC CP 1243-1 DNP3 (All versions), SIMATIC CM 1542-1 (All versions before V2.0), SIMATIC CP 1542SP-1, CP 1542SP-1 IRC, and CP 1543SP-1 (All versions before to V1.0.15), SIMATIC CP 1543-1 (All versions before V2.1), SIMATIC RF650R, RF680R, RF685R (All versions before V3.0), SIMATIC CP 1616, CP 1604, DK-16xx PN IO (All versions before V2.7), SCALANCE X-200 (All versions before V5.2.2), SCALANCE X200 IRT (All versions before V5.4.0), SCALANCE X-300/X408 (All versions before V4.1.0), SCALANCE X414 (All versions before V3.10.2), SCALANCE XM400, XR500 (All versions before V6.1), SCALANCE W700 (All versions before V6.1), SCALANCE M-800, S615 (All versions before V04.03), Softnet PROFINET IO for PC-based Windows systems (All versions before V14 SP1), IE/PB-Link (All versions before V3.0), IE/AS-i Link PN IO (All versions), SIMATIC Teleservice Adapter Standard Modem, IE Basic, IE Advanced (All versions), SITOP PSU8600 PROFINET (All versions before V1.2.0), SITOP UPS1600 PROFINET (All versions before V2.2.0), SIMATIC ET 200AL (All versions before V1.0.2), SIMATIC ET 200ecoPN (All versions), SIMATIC ET 200M (All versions), SIMATIC ET 200MP (All versions before V4.0.1), SIMATIC ET 200pro (All versions), SIMATIC ET 200S (All versions), SIMATIC ET 200SP (All versions before V4.1.0), SIMATIC PN/PN Coupler (All versions before V4.0), DK Standard Ethernet Controller (All versions before V4.1.1 Patch04), EK-ERTEC 200P PN IO (All versions before V4.4.0 Patch01), EK-ERTEC 200 PN IO (All versions before V4.2.1 Patch03), SIMATIC S7-200 SMART (All versions before V2.3), SIMATIC S7-300 incl. F and T (All versions before V3.X.14), SIMATIC S7-400 PN/DP V6 Incl. F (All versions before V6.0.6), SIMATIC S7-400-H V6 (All versions before V6.0.7), SIMATIC S7-400 PN/DP V7 incl. F (All versions), SIMATIC S7-CPU 410 (All versions before V8.2), SIMATIC S7-1200 incl. F (All versions before V4.2.1), SIMATIC S7-1500 incl. F, T, and TF (All versions before V2.1), SIMATIC S7-1500 Software Controller incl. F (All versions before V2.1), SIMATIC WinAC RTX 2010 incl. F (All versions), SIRIUS ACT 3SU1 interface module PROFINET (All versions), SIRIUS Soft starter 3RW44 PN (All versions), SIRIUS Motor starter M200D PROFINET (All versions), SIMOCODE pro V PROFINET (All versions), SINAMICS DCM (All versions before V1.4 SP1 HF5), SINAMICS DCP (All versions), SINAMICS G110M / G120(C/P/D) w. PN (All versions before V4.7 SP6 HF3), SINAMICS G130 and G150 (All versions before V4.7 HF27 and V4.8 before HF4), SINAMICS S110 w. PN (All versions before V4.4 SP1 HF5), SINAMICS S120 (All versions before V4.7 HF27 and V4.8 before HF4), SINAMICS S150 (All versions before V4.7 HF27 and V4.8 before HF4), SINAMICS V90 w. PN (All versions before V1.1), SIMOTION (All versions before V4.5 HF1), SINUMERIK 828D (All versions before V4.5 SP6 HF2 and V4.7 before SP6 HF8), SINUMERIK 840D sl (All versions before V4.5 SP6 HF8 and V4.7 before SP4 HF1), SIMATIC HMI Comfort Panels, HMI Multi Panels, HMI Mobile Panels (All versions) could be affected by a Denial-of-Service condition induced by a specially crafted PROFINET DCP broadcast (Layer 2 - Ethernet) packet."
|
|
}
|
|
]
|
|
},
|
|
"problemtype" : {
|
|
"problemtype_data" : [
|
|
{
|
|
"description" : [
|
|
{
|
|
"lang" : "eng",
|
|
"value" : "CWE-20: Improper Input Validation"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
"references" : {
|
|
"reference_data" : [
|
|
{
|
|
"name" : "https://ics-cert.us-cert.gov/advisories/ICSA-18-023-02",
|
|
"refsource" : "MISC",
|
|
"url" : "https://ics-cert.us-cert.gov/advisories/ICSA-18-023-02"
|
|
},
|
|
{
|
|
"name" : "https://cert-portal.siemens.com/productcert/pdf/ssa-293562.pdf",
|
|
"refsource" : "CONFIRM",
|
|
"url" : "https://cert-portal.siemens.com/productcert/pdf/ssa-293562.pdf"
|
|
},
|
|
{
|
|
"name" : "https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-284673.pdf",
|
|
"refsource" : "CONFIRM",
|
|
"url" : "https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-284673.pdf"
|
|
},
|
|
{
|
|
"name" : "https://cert-portal.siemens.com/productcert/pdf/ssa-546832.pdf",
|
|
"refsource" : "CONFIRM",
|
|
"url" : "https://cert-portal.siemens.com/productcert/pdf/ssa-546832.pdf"
|
|
},
|
|
{
|
|
"name" : "98369",
|
|
"refsource" : "BID",
|
|
"url" : "http://www.securityfocus.com/bid/98369"
|
|
},
|
|
{
|
|
"name" : "1038463",
|
|
"refsource" : "SECTRACK",
|
|
"url" : "http://www.securitytracker.com/id/1038463"
|
|
}
|
|
]
|
|
}
|
|
}
|