Siemens
Siemens Simatic S7-1500 Firmware: vulnerabilidades y CVE
Siemens Simatic S7-1500 Firmware tiene 13 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses0
Críticas0
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2014-0160 | Alta (7.5) | 100% | ⚠ Explotación activa | 7 abr 2014 | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-8744 | Alta (7.8) | 0.36% | — | 12 nov 2020 | Improper initialization in subsystem for Intel(R) CSME versions before12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 4.0.30 Intel(R) SPS versions before E3_05.01.04.200 may allow a… |
| CVE-2019-6575 | Alta (7.5) | 1.6% | — | 17 abr 2019 | A vulnerability has been identified in SIMATIC CP 443-1 OPC UA (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V2.7), SIMATIC HMI Comfort Outdoor Panels 7" & 15"… |
| CVE-2019-6568 | Alta (7.5) | 1.4% | — | 17 abr 2019 | The webserver of the affected devices contains a vulnerability that may lead to a denial of service condition. An attacker may cause a denial of service situation which leads to a restart of the webserver of the… |
| CVE-2018-16559 | Alta (7.5) | 2.0% | — | 17 abr 2019 | A vulnerability has been identified in SIMATIC S7-1500 CPU (All versions >= V2.0 and < V2.5), SIMATIC S7-1500 CPU (All versions <= V1.8.5). Specially crafted network packets sent to port 80/tcp or 443/tcp could allow an… |
| CVE-2018-16558 | Alta (7.5) | 2.0% | — | 17 abr 2019 | A vulnerability has been identified in SIMATIC S7-1500 CPU (All versions >= V2.0 and < V2.5), SIMATIC S7-1500 CPU (All versions <= V1.8.5). Specially crafted network packets sent to port 80/tcp or 443/tcp could allow an… |
| CVE-2018-13815 | Alta (7.5) | 1.8% | — | 13 dic 2018 | A vulnerability has been identified in SIMATIC S7-1200 (All versions), SIMATIC S7-1500 (All Versions < V2.6). An attacker could exhaust the available connection pool of an affected device by opening a sufficient number… |
| CVE-2018-13805 | Alta (7.5) | 1.5% | — | 10 oct 2018 | A vulnerability has been identified in SIMATIC ET 200SP Open Controller (All versions >= V2.0 and < V2.1.6), SIMATIC S7-1500 Software Controller (All versions >= V2.0 and < V2.5), SIMATIC S7-1500 incl. F (All versions… |
| CVE-2018-3639 | Media (5.5) | 61% | — | 22 may 2018 | Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an… |
| CVE-2018-4843 | Media (6.5) | 0.54% | — | 20 mar 2018 | A vulnerability has been identified in SIMATIC S7-400 CPU 414-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 414F-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 416-3 PN/DP V7 (All versions < V7.0.3),… |
| CVE-2017-12741 | Alta (8.7) | 3.3% | — | 26 dic 2017 | Specially crafted packets sent to port 161/udp could cause a denial of service condition. The affected devices must be restarted manually. |
| CVE-2017-2681 | Alta (7.1) | 0.91% | — | 11 may 2017 | Specially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a denial of service condition of that product. Human interaction is required to recover the system.… |
| CVE-2017-2680 | Alta (7.1) | 1.1% | — | 11 may 2017 | Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2). Human interaction is required to recover the systems. PROFIBUS… |
| CVE-2014-0160 | Alta (7.5) | 100% | ⚠ Explotación activa | 7 abr 2014 | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.