CVE-2020-15783

moderate-risk
Published 2020-11-12

A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC TDC CPU555 (All versions), SINUMERIK 840D sl (All versions). Sending multiple specially crafted packets to the affected devices could cause a Denial-of-Service on port 102. A cold restart is required to recover the service.

Do I need to act?

-
0.19% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10 High
NETWORK / LOW complexity

Affected Products (12)

Sinumerik 840D Sl Firmware
Simatic S7-300 Cpu 312 Firmware
Simatic S7-300 Cpu 314 Firmware
Simatic S7-300 Cpu 315-2 Dp Firmware
Simatic S7-300 Cpu 315-2 Pn Firmware
Simatic S7-300 Cpu 317-2 Pn Firmware
Simatic S7-300 Cpu 317-2 Dp Firmware
Simatic S7-300 Cpu 315F-2 Dp Firmware
Simatic S7-300 Cpu 315F-2 Pn Firmware
Simatic S7-300 Cpu 317F-2 Pn Firmware
Simatic S7-300 Cpu 317F-2 Dp Firmware
Simatic Tdc Cpu555 Firmware

Affected Vendors

44
/ 100
moderate-risk
Severity 26/34 · High
Exploitability 1/34 · Minimal
Exposure 17/34 · Moderate