CVE-2017-6865

CVSS V2 Medium 6.1 CVSS V3 Medium 6.5
Description
A vulnerability has been identified in Primary Setup Tool (PST) (All versions < V4.2 HF1), SIMATIC Automation Tool (All versions < V3.0), SIMATIC NET PC-Software (All versions < V14 SP1), SIMATIC PCS 7 V8.1 (All versions), SIMATIC PCS 7 V8.2 (All versions < V8.2 SP1), SIMATIC STEP 7 (TIA Portal) V13 (All versions < V13 SP2), SIMATIC STEP 7 (TIA Portal) V14 (All versions < V14 SP1), SIMATIC STEP 7 V5.X (All versions < V5.6), SIMATIC WinAC RTX 2010 SP2 (All versions), SIMATIC WinAC RTX F 2010 SP2 (All versions), SIMATIC WinCC (TIA Portal) V13 (All versions < V13 SP2), SIMATIC WinCC (TIA Portal) V14 (All versions < V14 SP1), SIMATIC WinCC V7.2 and prior (All versions), SIMATIC WinCC V7.3 (All versions < V7.3 Update 15), SIMATIC WinCC V7.4 (All versions < V7.4 SP1 Upd1), SIMATIC WinCC flexible 2008 (All versions < flexible 2008 SP5), SINAUT ST7CC (All versions installed in conjunction with SIMATIC WinCC < V7.3 Update 15), SINEMA Server (All versions < V14), SINUMERIK 808D Programming Tool (All versions < V4.7 SP4 HF2), SMART PC Access (All versions < V2.3), STEP 7 - Micro/WIN SMART (All versions < V2.3), Security Configuration Tool (SCT) (All versions < V5.0). Specially crafted PROFINET DCP broadcast packets sent to the affected products on a local Ethernet segment (Layer 2) could cause a Denial-of-Service condition of some services. The services require manual restart to recover.
Overview
  • CVE ID
  • CVE-2017-6865
  • Assigner
  • productcert@siemens.com
  • Vulnerability Status
  • Modified
  • Published Version
  • 2017-05-11T10:29:00
  • Last Modified Date
  • 2019-03-21T16:29:00
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:siemens:pcs_7:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:primary_setup_tool:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:security_configuration_tool:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:simatic_automation_tool:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:simatic_net_pc-software:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:simatic_step_7_\(tia_portal\):5.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:simatic_step_7_\(tia_portal\):13.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:simatic_step_7_\(tia_portal\):14.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:simatic_step_7_micro\/win_smart:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:simatic_winac_rtx_2010:-:sp2:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:simatic_winac_rtx_f_2010:-:sp2:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:simatic_wincc:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:simatic_wincc_\(tia_portal\):13.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:simatic_wincc_\(tia_portal\):14.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:simatic_wincc_flexible_2008:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:sinaut_st7cc:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:sinema_server:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:sinumerik_808d_programming_tool:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:siemens:smart_pc_access:2.0:*:*:*:*:*:*:* 1 OR
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:A/AC:L/Au:N/C:N/I:N/A:C
  • Access Vector
  • ADJACENT_NETWORK
  • Access Compatibility
  • LOW
  • Authentication
  • NONE
  • Confidentiality Impact
  • NONE
  • Integrity Impact
  • NONE
  • Availability Impact
  • COMPLETE
  • Base Score
  • 6.1
  • Severity
  • MEDIUM
  • Exploitability Score
  • 6.5
  • Impact Score
  • 6.9
CVSS Version 3
  • Version
  • 3.0
  • Vector String
  • CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Attack Vector
  • ADJACENT_NETWORK
  • Attack Compatibility
  • LOW
  • Privileges Required
  • NONE
  • User Interaction
  • NONE
  • Scope
  • UNCHANGED
  • Confidentiality Impact
  • NONE
  • Availability Impact
  • HIGH
  • Base Score
  • 6.5
  • Base Severity
  • MEDIUM
  • Exploitability Score
  • 2.8
  • Impact Score
  • 3.6
History
Created Old Value New Value Data Type Notes
2022-05-10 17:46:19 Added to TrackCVE
2022-12-02 16:45:07 2017-05-11T10:29Z 2017-05-11T10:29:00 CVE Published Date updated
2022-12-02 16:45:07 2019-03-21T16:29:00 CVE Modified Date updated
2022-12-02 16:45:07 Modified Vulnerability Status updated