A vulnerability has been identified in OpenPCS 7 V8.1 (All versions), OpenPCS 7 V8.2 (All versions), OpenPCS 7 V9.0 (All versions < V9.0 Upd3), SIMATIC BATCH V8.1 (All versions), SIMATIC BATCH V8.2 (All versions < V8.2 Upd12), SIMATIC BATCH V9.0 (All versions < V9.0 SP1 Upd5), SIMATIC NET PC Software V14 (All versions < V14 SP1 Update 14), SIMATIC NET PC Software V15 (All versions), SIMATIC NET PC Software V16 (All versions < V16 Update 1), SIMATIC PCS 7 V8.1 (All versions), SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3), SIMATIC Route Control V8.1 (All versions), SIMATIC Route Control V8.2 (All versions), SIMATIC Route Control V9.0 (All versions < V9.0 Upd4), SIMATIC WinCC (TIA Portal) V13 (All versions < V13 SP2), SIMATIC WinCC (TIA Portal) V14 (All versions < V14 SP1 Update 10), SIMATIC WinCC (TIA Portal) V15.1 (All versions < V15.1 Update 5), SIMATIC WinCC (TIA Portal) V16 (All versions < V16 Update 1), SIMATIC WinCC V7.3 (All versions), SIMATIC WinCC V7.4 (All versions < V7.4 SP1 Update 14), SIMATIC WinCC V7.5 (All versions < V7.5 SP1 Update 1). Through specially crafted messages, when encrypted communication is enabled, an attacker with network access could use the vulnerability to compromise the availability of the system by causing a Denial-of-Service condition. Successful exploitation requires no system privileges and no user interaction.
The product does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openpcs_7 | Siemens | 9.0 (including) | 9.0 (including) |
Openpcs_7 | Siemens | 9.0_update_1 (including) | 9.0_update_1 (including) |
Simatic_batch | Siemens | 9.0 (including) | 9.0 (including) |
Simatic_batch | Siemens | 9.0-sp1 (including) | 9.0-sp1 (including) |
Simatic_batch | Siemens | 9.0-sp1_update_1 (including) | 9.0-sp1_update_1 (including) |
Simatic_batch | Siemens | 9.0-sp1_update_2 (including) | 9.0-sp1_update_2 (including) |
Simatic_batch | Siemens | 9.0-sp1_update_3 (including) | 9.0-sp1_update_3 (including) |
Simatic_batch | Siemens | 9.0-sp1_update_4 (including) | 9.0-sp1_update_4 (including) |
Simatic_net_pc | Siemens | * | 16 (excluding) |
Simatic_net_pc | Siemens | 16 (including) | 16 (including) |
Simatic_pcs_7 | Siemens | 8.1 (including) | 8.1 (including) |
Simatic_pcs_7 | Siemens | 8.2 (including) | 8.2 (including) |
Simatic_pcs_7 | Siemens | 9.0 (including) | 9.0 (including) |
Simatic_pcs_7 | Siemens | 9.0-sp1 (including) | 9.0-sp1 (including) |
Simatic_pcs_7 | Siemens | 9.0-sp2 (including) | 9.0-sp2 (including) |
Simatic_route_control | Siemens | * | 9.0 (excluding) |
Simatic_route_control | Siemens | 9.0 (including) | 9.0 (including) |
Simatic_wincc | Siemens | 7.4 (including) | 7.4 (including) |
Simatic_wincc | Siemens | 7.4-sp1 (including) | 7.4-sp1 (including) |
Simatic_wincc | Siemens | 7.4-sp1_update_1 (including) | 7.4-sp1_update_1 (including) |
Simatic_wincc | Siemens | 7.4-sp1_update_10 (including) | 7.4-sp1_update_10 (including) |
Simatic_wincc | Siemens | 7.4-sp1_update_11 (including) | 7.4-sp1_update_11 (including) |
Simatic_wincc | Siemens | 7.4-sp1_update_12 (including) | 7.4-sp1_update_12 (including) |
Simatic_wincc | Siemens | 7.4-sp1_update_13 (including) | 7.4-sp1_update_13 (including) |
Simatic_wincc | Siemens | 7.4-sp1_update_2 (including) | 7.4-sp1_update_2 (including) |
Simatic_wincc | Siemens | 7.4-sp1_update_3 (including) | 7.4-sp1_update_3 (including) |
Simatic_wincc | Siemens | 7.4-sp1_update_4 (including) | 7.4-sp1_update_4 (including) |
Simatic_wincc | Siemens | 7.4-sp1_update_5 (including) | 7.4-sp1_update_5 (including) |
Simatic_wincc | Siemens | 7.4-sp1_update_6 (including) | 7.4-sp1_update_6 (including) |
Simatic_wincc | Siemens | 7.4-sp1_update_7 (including) | 7.4-sp1_update_7 (including) |
Simatic_wincc | Siemens | 7.4-sp1_update_8 (including) | 7.4-sp1_update_8 (including) |
Simatic_wincc | Siemens | 7.4-sp1_update_9 (including) | 7.4-sp1_update_9 (including) |
Simatic_wincc | Siemens | 7.5 (including) | 7.5 (including) |
Simatic_wincc | Siemens | 7.5-sp1 (including) | 7.5-sp1 (including) |
Simatic_wincc | Siemens | 7.5.1 (including) | 7.5.1 (including) |
Simatic_wincc | Siemens | 13 (including) | 13 (including) |
Simatic_wincc | Siemens | 13-sp1 (including) | 13-sp1 (including) |
Simatic_wincc | Siemens | 14.0.1 (including) | 14.0.1 (including) |
Simatic_wincc | Siemens | 15.1 (including) | 15.1 (including) |
Simatic_wincc | Siemens | 15.1-update_1 (including) | 15.1-update_1 (including) |
Simatic_wincc | Siemens | 15.1-update_2 (including) | 15.1-update_2 (including) |
Simatic_wincc | Siemens | 15.1-update_3 (including) | 15.1-update_3 (including) |
Simatic_wincc | Siemens | 15.1-update_4 (including) | 15.1-update_4 (including) |
Simatic_wincc | Siemens | 16 (including) | 16 (including) |