VendorsSiemenssimatic_s7-1500_software_controller_firmwareany version
Vulnerabilities

Siemens SIMATIC S7-1500 Software Controller Firmware any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2023-28831
The OPC UA implementations (ANSI C and C++) in affected products contain an integer overflow vulnerability that could cause the application to run into an infinite loop during certificate validation. This could allow an unauthenticated remote attacker to create a denial of service condition by sending a specially crafted certificate.
Published 2023-09-12 · Modified
8.7EPSS 0.011
CVE-2020-15796
A vulnerability has been identified in SIMATIC ET 200SP Open Controller (incl. SIPLUS variants) (V20.8), SIMATIC S7-1500 Software Controller (V20.8). The web server of the affected products contains a vulnerability that could allow a remote attacker to trigger a denial-of-service condition by sending a specially crafted HTTP request.
Published 2020-12-14 · Modified
7.5EPSS 0.016
CVE-2023-46156
Affected devices improperly handle specially crafted packets sent to port 102/tcp. This could allow an attacker to create a denial of service condition. A restart is needed to restore normal operations.
Published 2023-12-12 · Modified
7.5EPSS 0.012
CVE-2021-40365
Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.
Published 2022-12-13 · Modified
7.5EPSS 0.009
CVE-2021-44693
Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.
Published 2022-12-13 · Modified
7.5EPSS 0.007
CVE-2021-44695
Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.
Published 2022-12-13 · Modified
7.5EPSS 0.007
CVE-2021-44694
Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.
Published 2022-12-13 · Modified
7.5EPSS 0.006
CVE-2017-2680
Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2). Human interaction is required to recover the systems. PROFIBUS interfaces are not affected.
Published 2017-05-11 · Modified
7.1EPSS 0.011