CVE-2013-2780: High severity siemens simatic s7-1200 cpu vulnerability
Published Apr 22, 2013
·Updated
Siemens SIMATIC S7-1200 PLCs 2.x and 3.x allow remote attackers to cause a denial of service (defect-mode transition and control outage) via crafted packets to UDP port 161 (aka the SNMP port).
Affected Software
18 affected components
Siemens Simatic S7-1200 Firmware<4.0
Siemens SIMATIC S7-1200
Siemens Simatic S7-1200 Cpu 1211c Firmware<4.0
Siemens Simatic S7-1200 Cpu 1211c
Siemens Simatic S7-1200 Cpu 1212c Firmware<4.0
Siemens Simatic S7-1200 Cpu 1212c
Siemens Simatic S7-1200 Cpu 1212fc Firmware<4.0
Siemens Simatic S7-1200 Cpu 1212fc
Siemens Simatic S7-1200 Cpu 1214 Fc Firmware<4.0
Siemens Simatic S7-1200 Cpu 1214 Fc
Siemens Simatic S7-1200 Cpu 1214c Firmware<4.0
Siemens Simatic S7-1200 Cpu 1214c
Siemens Simatic S7-1200 Cpu 1215 Fc Firmware<4.0
Siemens Simatic S7-1200 Cpu 1215 Fc
Siemens Simatic S7-1200 Cpu 1215c Firmware<4.0
Siemens Simatic S7-1200 Cpu 1215c
Siemens Simatic S7-1200 Cpu 1217c Firmware<4.0
Siemens Simatic S7-1200 Cpu 1217c
Event History
Apr 22, 2013
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-2780?
CVE-2013-2780 has a severity rating of medium, as it can cause a denial of service on affected devices.
2
How do I fix CVE-2013-2780?
To fix CVE-2013-2780, upgrade the firmware of the affected Siemens SIMATIC S7-1200 PLCs to version 4.0 or later.
3
Which devices are affected by CVE-2013-2780?
CVE-2013-2780 affects Siemens SIMATIC S7-1200 PLCs with firmware versions 2.x to 3.x.
4
What type of attack is associated with CVE-2013-2780?
CVE-2013-2780 is associated with remote denial of service attacks via crafted packets sent to UDP port 161.
5
Can CVE-2013-2780 lead to data loss?
CVE-2013-2780 primarily causes control outages but does not directly lead to data loss.