Vulnerability Details CVE-2021-40368
A vulnerability has been identified in SIMATIC S7-400 CPU 412-1 DP V7 (All versions), SIMATIC S7-400 CPU 412-2 DP V7 (All versions), SIMATIC S7-400 CPU 412-2 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 414-2 DP V7 (All versions), SIMATIC S7-400 CPU 414-3 DP V7 (All versions), SIMATIC S7-400 CPU 414-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 414F-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 416-2 DP V7 (All versions), SIMATIC S7-400 CPU 416-3 DP V7 (All versions), SIMATIC S7-400 CPU 416-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 416F-2 DP V7 (All versions), SIMATIC S7-400 CPU 416F-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 417-4 DP V7 (All versions), SIMATIC S7-400 H V6 CPU family (incl. SIPLUS variants) (All versions < V6.0.10), SIMATIC S7-410 V10 CPU family (incl. SIPLUS variants) (All versions < V10.1), SIMATIC S7-410 V8 CPU family (incl. SIPLUS variants) (All versions < V8.2.3), SIPLUS S7-400 CPU 414-3 PN/DP V7 (All versions < V7.0.3), SIPLUS S7-400 CPU 416-3 PN/DP V7 (All versions < V7.0.3), SIPLUS S7-400 CPU 416-3 V7 (All versions), SIPLUS S7-400 CPU 417-4 V7 (All versions). Affected devices improperly handle specially crafted packets sent to port 102/tcp.
This could allow an attacker to create a Denial-of-Service condition. A restart is needed to restore normal operations.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 54.5%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2021-40368
-
cpe:2.3:h:siemens:simatic_s7-400_pn/dp_v7:-
-
cpe:2.3:h:siemens:simatic_s7-400h_v6:-
-
cpe:2.3:h:siemens:simatic_s7-410_v10:-
-
cpe:2.3:h:siemens:simatic_s7-410_v8:-
-
cpe:2.3:o:siemens:simatic_s7-400_pn/dp_v7_firmware:-
-
cpe:2.3:o:siemens:simatic_s7-400h_v6_firmware:-
-
cpe:2.3:o:siemens:simatic_s7-400h_v6_firmware:6.0.8
-
cpe:2.3:o:siemens:simatic_s7-400h_v6_firmware:6.0.9
-
cpe:2.3:o:siemens:simatic_s7-410_v10_firmware:-
-
cpe:2.3:o:siemens:simatic_s7-410_v8_firmware:-
-
cpe:2.3:o:siemens:simatic_s7-410_v8_firmware:8.2.2