Vulnerability Description
Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Simatic S7-Plcsim Advanced Firmware | < 5.0 |
| Siemens | Simatic S7-Plcsim Advanced | - |
| Siemens | Simatic S7-1200 Cpu 1211C Firmware | < 4.6.0 |
| Siemens | Simatic S7-1200 Cpu 1211C | - |
| Siemens | Simatic S7-1200 Cpu 1212C Firmware | < 4.6.0 |
| Siemens | Simatic S7-1200 Cpu 1212C | - |
| Siemens | Simatic S7-1200 Cpu 1212Fc Firmware | < 4.6.0 |
| Siemens | Simatic S7-1200 Cpu 1212Fc | - |
| Siemens | Simatic S7-1200 Cpu 1214 Fc Firmware | < 4.6.0 |
| Siemens | Simatic S7-1200 Cpu 1214 Fc | - |
| Siemens | Simatic S7-1200 Cpu 1214C Firmware | < 4.6.0 |
| Siemens | Simatic S7-1200 Cpu 1214C | - |
| Siemens | Simatic S7-1200 Cpu 1214Fc Firmware | < 4.6.0 |
| Siemens | Simatic S7-1200 Cpu 1214Fc | - |
| Siemens | Simatic S7-1200 Cpu 1215 Fc Firmware | < 4.6.0 |
| Siemens | Simatic S7-1200 Cpu 1215 Fc | - |
| Siemens | Simatic S7-1200 Cpu 1215C Firmware | < 4.6.0 |
| Siemens | Simatic S7-1200 Cpu 1215C | - |
| Siemens | Simatic S7-1200 Cpu 1215Fc Firmware | < 4.6.0 |
| Siemens | Simatic S7-1200 Cpu 1215Fc | - |
Related Weaknesses (CWE)
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-382653.pdfPatchVendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-382653.pdfPatchVendor Advisory
FAQ
What is CVE-2021-40365?
CVE-2021-40365 is a vulnerability with a CVSS score of 7.5 (HIGH). Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.
How severe is CVE-2021-40365?
CVE-2021-40365 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-40365?
Check the references section above for vendor advisories and patch information. Affected products include: Siemens Simatic S7-Plcsim Advanced Firmware, Siemens Simatic S7-Plcsim Advanced, Siemens Simatic S7-1200 Cpu 1211C Firmware, Siemens Simatic S7-1200 Cpu 1211C, Siemens Simatic S7-1200 Cpu 1212C Firmware.