CVE-2016-2200: Input Validation
Published Feb 8, 2016
·Updated
Siemens SIMATIC S7-1500 CPU devices before 1.8.3 allow remote attackers to cause a denial of service (STOP mode transition) via crafted packets on TCP port 102.
Affected Software
15 affected components
Siemens Simatic S7-1511-1 Pn Cpu
Siemens Simatic S7-1511c-1 Pn Cpu
Siemens Simatic S7-1511f-1 Pn Cpu
Siemens Simatic S7-1512c-1 Pn Cpu
Siemens Simatic S7-1513-1 Pn Cpu
Siemens Simatic S7-1513f-1 Pn Cpu
Siemens Simatic S7-1515-2 Pn Cpu
Siemens Simatic S7-1515f-2 Pn Cpu
Siemens Simatic S7-1516-3 Pn\/dp Cpu
Siemens Simatic S7-1516f-3 Pn\/dp Cpu
Siemens Simatic S7-1517-3 Pn\/dp Cpu
Siemens Simatic S7-1517f-3 Pn\/dp Cpu
Siemens Simatic S7-1518-4 Pn\/dp Cpu
Siemens Simatic S7-1518f-4 Pn\/dp Cpu
Siemens Simatic S7-1500 Cpu Firmware<=1.8.2
Event History
Feb 8, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-2200?
CVE-2016-2200 has a medium severity rating due to its ability to cause a denial of service condition.
2
How do I fix CVE-2016-2200?
To mitigate CVE-2016-2200, upgrade the Siemens SIMATIC S7-1500 CPU firmware to version 1.8.3 or later.
3
Which devices are affected by CVE-2016-2200?
CVE-2016-2200 affects Siemens SIMATIC S7-1500 CPU devices running firmware versions prior to 1.8.3.
4
Can exploiting CVE-2016-2200 lead to data loss?
Exploiting CVE-2016-2200 may result in a denial of service, causing potential disruptions but not directly leading to data loss.
5
What type of attack is associated with CVE-2016-2200?
CVE-2016-2200 is associated with a remote denial of service attack through crafted packets sent to TCP port 102.