Release date:
Updated on:
Affected Systems:
Siemens SIMATIC S7-1200
Description:
--------------------------------------------------------------------------------
Bugtraq id: 66344
CVE (CAN) ID: CVE-2014-2258
The SIMATIC S7-1200 is a programmable controller that enables simple but highly precise automation tasks.
A denial of service vulnerability exists in implementation in versions earlier than SIMATIC S7-1200 4.0. If attackers send specially crafted packets to port 443/tcp (HTTPS), the affected devices may enter defect mode, as a result, the system rejects services and requires cold start.
<* Source: vendor
Link: http://www.securelist.com/en/advisories/57441
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Siemens
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-654382.pdf