CVE-2021-44693

MEDIUMCVSS 4.9/10EPSS 0.72%

Last modified

CVE-2021-44693 is a medium-severity vulnerability rated 4.9/10 on the CVSS scale. Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.. EPSS estimates a 0.72% chance of exploitation in the next 30 days.

Description

Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.

Metrics

CVSS 3.1
4.9/10

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
0.72%

49.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
SiemensSimatic S7-Plcsim Advanced Firmware< 5.0
SiemensSimatic S7-1200 Cpu 1211c Firmware< 4.6.0
SiemensSimatic S7-1200 Cpu 1212c Firmware< 4.6.0
SiemensSimatic S7-1200 Cpu 1212fc Firmware< 4.6.0
SiemensSimatic S7-1200 Cpu 1214 Fc Firmware< 4.6.0
SiemensSimatic S7-1200 Cpu 1214c Firmware< 4.6.0
SiemensSimatic S7-1200 Cpu 1214fc Firmware< 4.6.0
SiemensSimatic S7-1200 Cpu 1215 Fc Firmware< 4.6.0
SiemensSimatic S7-1200 Cpu 1215c Firmware< 4.6.0
SiemensSimatic S7-1200 Cpu 1215fc Firmware< 4.6.0
SiemensSimatic S7-1200 Cpu 1217c Firmware< 4.6.0
SiemensSimatic S7-1200 Cpu 12 1211c Firmware< 4.6.0
SiemensSimatic S7-1200 Cpu 12 1212c Firmware< 4.6.0
SiemensSimatic S7-1200 Cpu 12 1212fc Firmware< 4.6.0
SiemensSimatic S7-1200 Cpu 12 1214c Firmware< 4.6.0
SiemensSimatic S7-1200 Cpu 12 1214fc Firmware< 4.6.0
SiemensSimatic S7-1200 Cpu 12 1215c Firmware< 4.6.0
SiemensSimatic S7-1200 Cpu 12 1215fc Firmware< 4.6.0
SiemensSimatic S7-1200 Cpu 12 1217c Firmware< 4.6.0
SiemensSiplus S7-1200 Cp 1243-1 Rail Firmware< 4.6.0
SiemensSiplus S7-1200 Cp 1243-1 Firmware< 4.6.0
SiemensSimatic S7-1500 Cpu 1507s Firmware< 3.0.1
SiemensSimatic S7-1500 Cpu 1507s F Firmware< 3.0.1
SiemensSimatic S7-1500 Cpu 1508s Firmware< 3.0.1
SiemensSimatic S7-1500 Cpu 1508s F Firmware< 3.0.1
SiemensSimatic S7-1500 Cpu 1510sp Firmware< 3.0.1
SiemensSimatic S7-1500 Cpu 1510sp-1 Firmware< 3.0.1
SiemensSimatic S7-1500 Cpu 1511-1 Firmware< 3.0.1
SiemensSimatic S7-1500 Cpu 1511-1 Pn Firmware< 3.0.1
SiemensSimatic S7-1500 Cpu 1511c Firmware< 3.0.1
SiemensSimatic S7-1500 Cpu 1511c-1 Firmware< 3.0.1
SiemensSimatic S7-1500 Cpu 1511f-1 Firmware< 3.0.1
SiemensSimatic S7-1500 Cpu 1511f-1 Pn Firmware< 3.0.1
SiemensSimatic S7-1500 Cpu 1511t-1 Firmware< 3.0.1
SiemensSimatic S7-1500 Cpu 1511tf-1 Firmware< 3.0.1
SiemensSimatic S7-1500 Cpu 1512c Firmware< 3.0.1
SiemensSimatic S7-1500 Cpu 1512c-1 Firmware< 3.0.1
SiemensSimatic S7-1500 Cpu 1512sp-1 Firmware< 3.0.1
SiemensSimatic S7-1500 Cpu 1512spf-1 Firmware< 3.0.1
SiemensSimatic S7-1500 Cpu 1513-1 Firmware< 3.0.1
SiemensSimatic S7-1500 Cpu 1513-1 Pn Firmware< 3.0.1
SiemensSimatic S7-1500 Cpu 1513f-1 Firmware< 3.0.1
SiemensSimatic S7-1500 Cpu 1513f-1 Pn Firmware< 3.0.1
SiemensSimatic S7-1500 Cpu 1513r-1 Firmware< 3.0.1
SiemensSimatic S7-1500 Cpu 1515-2 Firmware< 3.0.1
SiemensSimatic S7-1500 Cpu 1515-2 Pn Firmware< 3.0.1
SiemensSimatic S7-1500 Cpu 151511c-1 Firmware< 3.0.1
SiemensSimatic S7-1500 Cpu 151511f-1 Firmware< 3.0.1
SiemensSimatic S7-1500 Cpu 1515f-2 Firmware< 3.0.1
SiemensSimatic S7-1500 Cpu 1515f-2 Pn Firmware< 3.0.1

Showing 50 of 96 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-44693?
Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.
How severe is CVE-2021-44693?
CVE-2021-44693 has a CVSS score of 4.9/10 (MEDIUM severity). The EPSS model estimates a 0.72% probability of exploitation in the next 30 days.
How do I fix CVE-2021-44693?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-44693?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST