

Rewterz Threat Alert – TA505 Crime Gang Deploys SDBbot for Corporate Network Takeover
April 15, 2020
RagnarLocker Ransomware Hits EDP Energy Giant for $10.9M
April 15, 2020
Rewterz Threat Alert – TA505 Crime Gang Deploys SDBbot for Corporate Network Takeover
April 15, 2020
RagnarLocker Ransomware Hits EDP Energy Giant for $10.9M
April 15, 2020Severity
Medium
Analysis Summary
CVE-2018-5390
Certain Linux kernel versions can be forced to make resource intensive calls for every incoming packet, which can lead to a denial-of-service condition.
CVE-2018-5391
Certain Linux kernels are vulnerable to a denial-of-service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause a denial-of-service condition by sending specially crafted IP fragments.
Impact
- Uncontrolled Resource Consumption
- Improper Input Validation
- Denial of service
Affected Vendors
Siemens
Affected Products
- IE/PB-Link v3 All versions
- RUGGEDCOM RM1224 All versions prior to 6.1
- RUGGEDCOM ROX II All versions prior to 2.13.3 (only affected by CVE-2018-5391)
- SCALANCE M-800 family All versions prior to 6.1
- SCALANCE S615 All versions prior to 6.1
- SCALANCE SC-600 All versions prior to 2.0
- SCALANCE W1700 IEEE 802.11ac All versions prior to 2.0
- SCALANCE W700 IEEE 802.11a/b/g/n All versions prior to 6.4
- SIMATIC CP 1242-7 All versions prior to 3.2
- SIMATIC CP 1243-1 (incl. SIPLUS NET variants) All versions prior to 3.2
- SIMATIC CP 1243-7 LTE EU All versions prior to 3.2
- SIMATIC CP 2243-7 LTE US: All versions prior to 3.2
- SIMATIC CP 1243-8 IRC: All versions prior to 3.2
- SIMATIC CP 1542SP-1 All versions prior to 2.1
- SIMATIC CP 1542SP-1 IRC (incl. SIPLUS NET variants) All versions prior to 2.1
- SIMATIC CP 1543SP-1 (incl. SIPLUS NET variants): All versions prior to 2.1
- SIMATIC RF185C: All versions
- SIMATIC RF186C All versions
- SINEMA Remote Connect Server: All versions newer than 1.1 and prior to 2.0.1
Remediation
Siemens recommends applying updates:
- RUGGEDCOM RM 1224: Update to v6.1
- RUGGEDCOM ROX II: Update to v2.13.3
- SCALANCE M-800 family: Update to v6.1
- SCALANCE S615: Update to v6.1
- SCALANCE SC-600: Update to v2.0 or later version
- SCALANCE W1700 IEEE 802.11 ac: Update to v2.0
- SCALANCE W700 IEEE 802.11a/b/g/n: Update to v6.4
- SIMATIC CP 1242-7 and 1243-1 (incl. SIPLUS NET variants): Update to v3.2
- SIMATIC CP 1243-7 LTE EU & US: Update to v3.2
- SIMATIC CP 1243-8 IRC: Update to v3.2
- SIMATIC CP 1542SP-1 and 1542SP-1 IRC (incl. SIPLUS NET variants): Update to v2.1
- SIMATIC 1543SP-1 IRC (incl. SIPLUS NET variants): Update to v2.1
- SIMATIC CP 1543-1 (incl. SIPLUS NET variants): Update to v2.2
- SIMATIC CP 1543SP-1 (incl. SIPLUS NET variants): Update to v2.1
- SINEMA Remote Connect Server: Update to v2.1