A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V21.9), SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (All versions < V4.5.0), SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions < V2.9.2), SIMATIC S7-1500 Software Controller (All versions < V21.9), SIMATIC S7-PLCSIM Advanced (All versions < V4.0), SINAMICS PERFECT HARMONY GH180 Drives (Drives manufactured before 2021-08-13), SINUMERIK MC (All versions < V6.15), SINUMERIK ONE (All versions < V6.15). Affected devices are vulnerable to a memory protection bypass through a specific operation. A remote unauthenticated attacker with network access to port 102/tcp could potentially write arbitrary data and code to protected memory areas or read sensitive data to launch further attacks.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Siemens
Subscribe
|
6es7510-1dj01-0ab0
Subscribe
6es7510-1sj01-0ab0
Subscribe
6es7511-1ak01-0ab0
Subscribe
6es7511-1ak02-0ab0
Subscribe
6es7511-1ck00-0ab0
Subscribe
6es7511-1ck01-0ab0
Subscribe
6es7511-1fk01-0ab0
Subscribe
6es7511-1fk02-0ab0
Subscribe
6es7511-1tk01-0ab0
Subscribe
6es7511-1uk01-0ab0
Subscribe
6es7512-1ck00-0ab0
Subscribe
6es7512-1ck01-0ab0
Subscribe
6es7512-1dk01-0ab0
Subscribe
6es7512-1sk01-0ab0
Subscribe
6es7513-1al01-0ab0
Subscribe
6es7513-1al02-0ab0
Subscribe
6es7513-1fl01-0ab0
Subscribe
6es7513-1fl02-0ab0
Subscribe
6es7513-1rl00-0ab0
Subscribe
6es7513-2gl00-0ab0
Subscribe
6es7513-2pl00-0ab0
Subscribe
6es7515-2am01-0ab0
Subscribe
6es7515-2am02-0ab0
Subscribe
6es7515-2fm01-0ab0
Subscribe
6es7515-2fm02-0ab0
Subscribe
6es7515-2rm00-0ab0
Subscribe
6es7515-2tm01-0ab0
Subscribe
6es7515-2um01-0ab0
Subscribe
6es7516-2gn00-0ab0
Subscribe
6es7516-2pn00-0ab0
Subscribe
6es7516-3an01-0ab0
Subscribe
6es7516-3an02-0ab0
Subscribe
6es7516-3fn01-0ab0
Subscribe
6es7516-3fn02-0ab0
Subscribe
6es7516-3tn00-0ab0
Subscribe
6es7516-3un00-0ab0
Subscribe
6es7517-3ap00-0ab0
Subscribe
6es7517-3fp00-0ab0
Subscribe
6es7517-3hp00-0ab0
Subscribe
6es7517-3tp00-0ab0
Subscribe
6es7517-3up00-0ab0
Subscribe
6es7518-4ap00-0ab0
Subscribe
6es7518-4ap00-3ab0
Subscribe
6es7518-4fp00-0ab0
Subscribe
6es7518-4fp00-3ab0
Subscribe
Cpu 1211c
Subscribe
Cpu 1212c
Subscribe
Cpu 1212fc
Subscribe
Cpu 1214c
Subscribe
Cpu 1214fc
Subscribe
Cpu 1215c
Subscribe
Cpu 1215fc
Subscribe
Cpu 1217c
Subscribe
Cpu 1504d Tf
Subscribe
Cpu 1507d Tf
Subscribe
Cpu 1515sp Pc
Subscribe
Cpu 1515sp Pc2
Subscribe
Et 200sp Open Controller Firmware
Subscribe
S7-1200 Cpu Firmware
Subscribe
S7-1500 Cpu Firmware
Subscribe
Simatic Driver Controller Firmware
Subscribe
Simatic S7-1500 Software Controller
Subscribe
Simatic S7-plcsim Advanced
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-7765 | A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V21.9), SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (All versions < V4.5.0), SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions < V2.9.2), SIMATIC S7-1500 Software Controller (All versions < V21.9), SIMATIC S7-PLCSIM Advanced (All versions < V4.0), SINAMICS PERFECT HARMONY GH180 Drives (Drives manufactured before 2021-08-13), SINUMERIK MC (All versions < V6.15), SINUMERIK ONE (All versions < V6.15). Affected devices are vulnerable to a memory protection bypass through a specific operation. A remote unauthenticated attacker with network access to port 102/tcp could potentially write arbitrary data and code to protected memory areas or read sensitive data to launch further attacks. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: siemens
Published:
Updated: 2024-08-04T13:22:30.758Z
Reserved: 2020-07-15T00:00:00
Link: CVE-2020-15782
No data.
Status : Modified
Published: 2021-05-28T16:15:07.790
Modified: 2024-11-21T05:06:10.140
Link: CVE-2020-15782
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD