Release date:
Updated on:
Affected Systems:
Siemens SIMATIC S7-1200 3.x
Siemens SIMATIC S7-1200 2.x
Siemens SIMATIC S7-1200
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57023
SIMATIC S7-1200 is a new PLC launched by Siemens, mainly for simple and high precision automation tasks.
Siemens simatic S7-1200 v2.x and 3. x is defective in handling SNMP status information and device management packets. attackers send specially crafted packets to 102/TCP (ISO-TSAP, device management port) or 161/UDP, the device can enter the fault mode, resulting in a denial of service.
<* Source: Prof. Dr. Hartmut Pohl
Arne Vidstrom (arne.vidstrom@ntsecurity.nu)
Link: http://secunia.com/advisories/51628/
Http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-7
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Siemens
-------
Siemens has released a Security Bulletin (ssa-724606) for this ):
Ssa-724606: SSA-724606: Denial-of-Service Vulnerabilities in SIMATIC S7-1200 PLCs
Link: http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-7