CVE Feed

    Dashboard / CVE / CVE-2018-13805

    CVE-2018-13805

    A vulnerability has been identified in SIMATIC ET 200SP Open Controller (All versions >= V2.0 and < V2.1.6), SIMATIC S7-1500 Software Controller (All versions >= V2.0 and < V2.5), SIMATIC S7-1500 incl. F (All versions >= V2.0 and < V2.5). An attacker can cause a denial-of-service condition on the network stack by sending a large number of specially crafted packets to the PLC. The PLC will lose its ability to communicate over the network. This vulnerability could be exploited by an attacker with network access to the affected systems. Successful exploitation requires no privileges and no user interaction. An attacker could use this vulnerability to compromise availability of the network connectivity. At the time of advisory publication no public exploitation of this vulnerability was known.

    Published:Oct 10, 2018
    Last Modified:Nov 21, 2024
    EPS:Oct 10, 2018
    EPSS Score:0.00495
    CVSS Score:7.5

    Affected Products

    Vendor
    Siemens
    Product
    Simatic Et 200sp
    Vendor
    Siemens
    Product
    Simatic Et 200sp Firmware
    Vendor
    Siemens
    Product
    Simatic S7-1500
    Vendor
    Siemens
    Product
    Simatic S7-1500 Firmware
    Vendor
    Siemens
    Product
    Simatic S7-1500f
    Vendor
    Siemens
    Product
    Simatic S7-1500f Firmware

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High