First published: Wed May 16 2018(Updated: )
A vulnerability has been identified in SIMATIC S7-400 (incl. F) CPU hardware version 4.0 and below (All versions), SIMATIC S7-400 (incl. F) CPU hardware version 5.0 (All firmware versions < V5.2), SIMATIC S7-400H CPU hardware version 4.5 and below (All versions). The affected CPUs improperly validate S7 communication packets which could cause a Denial-of-Service condition of the CPU. The CPU will remain in DEFECT mode until manual restart.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Simatic S7-400 Firmware | <=4.0 | |
Siemens Simatic S7-400 | ||
Siemens Simatic S7-400 Firmware | <5.2 | |
Siemens Simatic S7-400h Firmware | <=4.5 | |
Siemens Simatic S7-400h |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-4850 is high, with a severity value of 7.5.
SIMATIC S7-400 (incl. F) CPU hardware versions 4.0 and below, SIMATIC S7-400 (incl. F) CPU hardware version 5.0 (All firmware versions < V5.2), and SIMATIC S7-400H CPU hardware versions 4.5 and below are affected by CVE-2018-4850.
CVE-2018-4850 impacts Siemens SIMATIC S7-400 firmware versions 4.0 and below, as well as firmware versions 5.0 with a firmware version lower than V5.2.
No, Siemens Simatic S7-400h is not vulnerable to CVE-2018-4850.
The Common Weakness Enumeration (CWE) for CVE-2018-4850 is CWE-20.