A vulnerability was discovered in Siemens SIMATIC Logon (All versions before V1.6) that could allow specially crafted packets sent to the SIMATIC Logon Remote Access service on port 16389/tcp to cause a Denial-of-Service condition. The service restarts automatically.
The product writes data past the end, or before the beginning, of the intended buffer.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/99539 | third party advisory vdb entry |
https://www.tenable.com/security/research/tra-2017-34 | |
https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-804859.pdf | vendor advisory |