Simatic tia Portal Denial of Service Vulnerability (CVE-2015-2822)
Simatic tia Portal Denial of Service Vulnerability (CVE-2015-2822)
Release date:
Updated on:
Affected Systems:
Siemens SIMATIC WinCC (TIA Portal) <13 SP1 Upd2
Description:
CVE (CAN) ID: CVE-2015-2822
Siemens SIMATIC WinCC is a SCADA and HMI system for monitoring control and data collection.
SIMATIC WinCC Comfort Panels and SIMATIC WinCC Runtime Advanced have security vulnerabilities. Man-in-the-middle attackers who can access the network path between the HMI panel and the PLC can send constructed packets through TCP port 102, cause a denial of service.
<* Source: Quarkslab team
*>
Suggestion:
Vendor patch:
Siemens
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-487246.pdf
This article permanently updates the link address: