First published: Tue Apr 12 2022(Updated: )
A vulnerability has been identified in SIMATIC S7-400 CPU 412-1 DP V7 (All versions), SIMATIC S7-400 CPU 412-2 DP V7 (All versions), SIMATIC S7-400 CPU 412-2 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 414-2 DP V7 (All versions), SIMATIC S7-400 CPU 414-3 DP V7 (All versions), SIMATIC S7-400 CPU 414-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 414F-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 416-2 DP V7 (All versions), SIMATIC S7-400 CPU 416-3 DP V7 (All versions), SIMATIC S7-400 CPU 416-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 416F-2 DP V7 (All versions), SIMATIC S7-400 CPU 416F-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 417-4 DP V7 (All versions), SIMATIC S7-400 H V6 CPU family (incl. SIPLUS variants) (All versions < V6.0.10), SIMATIC S7-410 V10 CPU family (incl. SIPLUS variants) (All versions < V10.1), SIMATIC S7-410 V8 CPU family (incl. SIPLUS variants) (All versions < V8.2.3), SIPLUS S7-400 CPU 414-3 PN/DP V7 (All versions < V7.0.3), SIPLUS S7-400 CPU 416-3 PN/DP V7 (All versions < V7.0.3), SIPLUS S7-400 CPU 416-3 V7 (All versions), SIPLUS S7-400 CPU 417-4 V7 (All versions). Affected devices improperly handle specially crafted packets sent to port 102/tcp. This could allow an attacker to create a Denial-of-Service condition. A restart is needed to restore normal operations.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Simatic S7-400h V6 Firmware | <6.0.10 | |
Siemens Simatic S7-400h V6 | ||
Siemens Simatic S7-400 Pn\/dp V7 Firmware | ||
Siemens Simatic S7-400 Pn\/dp V7 | ||
Siemens Simatic S7-410 V8 Firmware | ||
Siemens Simatic S7-410 V8 | ||
Siemens Simatic S7-410 V10 Firmware | <10.1 | |
Siemens Simatic S7-410 V10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40368 is a vulnerability identified in SIMATIC S7-400 CPU 412-1 DP V7 and other versions.
The severity of CVE-2021-40368 is high with a severity value of 7.5.
Siemens Simatic S7-400h V6 Firmware up to version 6.0.10 is affected by CVE-2021-40368.
To fix CVE-2021-40368, it is recommended to update to a version that is not vulnerable.
You can find more information about CVE-2021-40368 in the reference link: https://cert-portal.siemens.com/productcert/pdf/ssa-557541.pdf