CVE-2021-37185

high-risk
Published 2022-02-09

A vulnerability has been identified in SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.4), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions >= V21.9 < V21.9.4), SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (All versions >= V4.5.0 < V4.5.2), SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions >= V2.9.2 < V2.9.4), SIMATIC S7-1500 Software Controller (All versions >= V21.9 < V21.9.4), SIMATIC S7-PLCSIM Advanced (All versions >= V4.0 < V4.0 SP1), SIPLUS TIM 1531 IRC (All versions < V2.3.6), TIM 1531 IRC (All versions < V2.3.6). An unauthenticated attacker could cause a denial-of-service condition in a PLC when sending specially prepared packets over port 102/tcp. A restart of the affected device is needed to restore normal operations.

Do I need to act?

~
2.0% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10 High
NETWORK / LOW complexity

Affected Products (20)

Simatic Drive Controller Cpu 1504D Tf Firmware
Simatic Drive Controller Cpu 1507D Tf Firmware
Simatic Et 200Sp Open Controller Cpu 1515Sp Pc2 Firmware
Simatic S7-Plcsim Advanced Firmware
Simatic S7-Plcsim Advanced Firmware
Tim 1531 Irc Firmware
Simatic S7-1500 Software Controller
Simatic S7-1200 Cpu 1211C Firmware
Simatic S7-1200 Cpu 1212C Firmware
Simatic S7-1200 Cpu 1212Fc Firmware
Simatic S7-1200 Cpu 1214Fc Firmware
Simatic S7-1200 Cpu 1214C Firmware
Simatic S7-1200 Cpu 1215Fc Firmware
Simatic S7-1200 Cpu 1215C Firmware
Simatic S7-1200 Cpu 1217C Firmware
Simatic S7-1500 Cpu 1510Sp-1 Firmware
Simatic S7-1500 Cpu 1510Sp Firmware
Simatic S7-1500 Cpu 1511-1 Firmware
Simatic S7-1500 Cpu 1511C-1 Firmware
Simatic S7-1500 Cpu 1511F-1 Firmware

Affected Vendors

56
/ 100
high-risk
Severity 26/34 · High
Exploitability 5/34 · Minimal
Exposure 25/34 · High