CVE-2018-13815: High severity siemens simatic s7-1200 cpu vulnerability
A vulnerability has been identified in SIMATIC S7-1200 (All versions), SIMATIC S7-1500 (All Versions < V2.6). An attacker could exhaust the available connection pool of an affected device by opening a sufficient number of connections to the device. Successful exploitation requires an attacker to be able to send packets to port 102/tcp of the affected device. No user interaction and no user privileges are required to exploit the vulnerability. The vulnerability, if exploited, could cause a Denial-of-Service condition impacting the availability of the system. At the time of advisory publication no public exploitation of this vulnerability was known.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
CVE-2018-13815
What is the severity level of CVE-2018-13815?
The severity level of CVE-2018-13815 is high.
Which software versions are affected by CVE-2018-13815?
SIMATIC S7-1200 (All versions), SIMATIC S7-1500 (All Versions < V2.6) are affected by CVE-2018-13815.
How can an attacker exploit CVE-2018-13815?
An attacker can exploit CVE-2018-13815 by exhausting the available connection pool of the affected device by opening a sufficient number of connections.
Are all versions of SIMATIC S7-1500 vulnerable to CVE-2018-13815?
No, only SIMATIC S7-1500 versions below V2.6 are vulnerable to CVE-2018-13815.