Vulnerability Details CVE-2018-13815
A vulnerability has been identified in SIMATIC S7-1200 (All versions), SIMATIC S7-1500 (All Versions < V2.6). An attacker could exhaust the available connection pool of an affected device by opening a sufficient number of connections to the device. Successful exploitation requires an attacker to be able to send packets to port 102/tcp of the affected device. No user interaction and no user privileges are required to exploit the vulnerability. The vulnerability, if exploited, could cause a Denial-of-Service condition impacting the availability of the system. At the time of advisory publication no public exploitation of this vulnerability was known.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 62.5%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2018-13815
-
cpe:2.3:h:siemens:simatic_s7-1200:-
-
cpe:2.3:h:siemens:simatic_s7-1500:-
-
cpe:2.3:o:siemens:simatic_s7-1200_firmware:-
-
cpe:2.3:o:siemens:simatic_s7-1500_firmware:-
-
cpe:2.3:o:siemens:simatic_s7-1500_firmware:1.5
-
cpe:2.3:o:siemens:simatic_s7-1500_firmware:1.7.0
-
cpe:2.3:o:siemens:simatic_s7-1500_firmware:1.8.5
-
cpe:2.3:o:siemens:simatic_s7-1500_firmware:2.0
-
cpe:2.3:o:siemens:simatic_s7-1500_firmware:2.1
-
cpe:2.3:o:siemens:simatic_s7-1500_firmware:2.5