ZeroHour

CVE-2021-37204

CVSS 3.1
7.5 high
EPSS
2%p81
Published
()
Modified
Description

A vulnerability has been identified in SIMATIC Drive Controller family (All versions = V2.9.2 = V21.9 = V4.5.0 = V2.9.2 = V21.9 = V4.0 < V4.0 SP1), SIPLUS TIM 1531 IRC (All versions < V2.3.6), TIM 1531 IRC (All versions < V2.3.6). An unauthenticated attacker could cause a denial-of-service condition in a PLC when sending specially prepared packet over port 102/tcp. A restart of the affected device is needed to restore normal operations.

Vendors
siemens
Products
simatic drive controller cpu 1504d tf firmware, simatic drive controller cpu 1507d tf firmware, simatic et 200sp open controller cpu 1515sp pc2 firmware, simatic s7-plcsim advanced firmware, tim 1531 irc firmware, simatic s7-1500 software controller, simatic s7-1200 cpu 1211c firmware, simatic s7-1200 cpu 1212c firmware, simatic s7-1200 cpu 1212fc firmware, simatic s7-1200 cpu 1214fc firmware, simatic s7-1200 cpu 1214c firmware, simatic s7-1200 cpu 1215fc firmware
Weakness
CWE-672
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.