CVE-2012-1800
Severity CVSS v4.0:
Pending analysis
Type:
CWE-119
Buffer Errors
Publication date:
18/04/2012
Last modified:
11/04/2025
Description
Stack-based buffer overflow in the Profinet DCP protocol implementation on the Siemens Scalance S Security Module firewall S602 V2, S612 V2, and S613 V2 with firmware before 2.3.0.3 allows remote attackers to cause a denial of service (device outage) or possibly execute arbitrary code via a crafted DCP frame.
Impact
Base Score 2.0
6.10
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:siemens:scalance_s_firmware:*:*:*:*:*:*:*:* | 2.3.0 (including) | |
| cpe:2.3:a:siemens:scalance_s_firmware:2.1.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:siemens:scalance_s_firmware:2.2.0:*:*:*:*:*:*:* | ||
| cpe:2.3:h:siemens:scalance_s602:v2:*:*:*:*:*:*:* | ||
| cpe:2.3:h:siemens:scalance_s612:v2:*:*:*:*:*:*:* | ||
| cpe:2.3:h:siemens:scalance_s613:v2:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://osvdb.org/81034
- http://support.automation.siemens.com/WW/view/en/59869684
- http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-268149.pdf
- http://www.us-cert.gov/control_systems/pdf/ICSA-12-102-05.pdf
- http://osvdb.org/81034
- http://support.automation.siemens.com/WW/view/en/59869684
- http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-268149.pdf
- http://www.us-cert.gov/control_systems/pdf/ICSA-12-102-05.pdf



