CVE-2017-2681

Severity CVSS v4.0:
HIGH
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
11/05/2017
Last modified:
20/04/2025

Description

Specially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a denial of service condition of that product. Human interaction is required to recover the system. PROFIBUS interfaces are not affected.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:siemens:simatic_cp_343-1_std_firmware:*:*:*:*:*:*:*:* 3.1.3 (excluding)
cpe:2.3:h:siemens:simatic_cp_343-1_std:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_cp_343-1_lean_firmware:*:*:*:*:*:*:*:* 3.1.3 (excluding)
cpe:2.3:h:siemens:simatic_cp_343-1_lean:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_cp_343-1_adv_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_cp_343-1_adv:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_cp_443-1_std_firmware:*:*:*:*:*:*:*:* 3.2.17 (excluding)
cpe:2.3:h:siemens:simatic_cp_443-1_std:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_cp_443-1_adv_firmware:*:*:*:*:*:*:*:* 3.2.17 (excluding)
cpe:2.3:h:siemens:simatic_cp_443-1_adv:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_cp_443-1_opc-ua_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_cp_443-1_opc-ua:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_cp_1243-1_firmware:*:*:*:*:*:*:*:* 2.1.82 (excluding)
cpe:2.3:h:siemens:simatic_cp_1243-1:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_cm_1542-1_firmware:*:*:*:*:*:*:*:* 2.0 (excluding)