CVE-2017-9945
In the Siemens 7KM PAC Switched Ethernet PROFINET expansion module (All versions < V2.1.3), a Denial-of-Service condition could be induced by a specially crafted PROFINET DCP packet sent as a local Ethernet (Layer 2) broadcast.
Does this matter?
Lower severity and a low EPSS score (0.54%). Track it; it rarely justifies an emergency change on its own.
Description
In the Siemens 7KM PAC Switched Ethernet PROFINET expansion module (All versions < V2.1.3), a Denial-of-Service condition could be induced by a specially crafted PROFINET DCP packet sent as a local Ethernet (Layer 2) broadcast. The affected component requires a manual restart via the main device to recover.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.54% probability · 44th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- siemens/7km pac switched ethernet profinet expansion module firmware
- Source
- productcert@siemens.com
References
- http://www.securityfocus.com/bid/100562Third Party Advisory, VDB Entry
- https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-771218.pdfVendor Advisory
- http://www.securityfocus.com/bid/100562Third Party Advisory, VDB Entry
- https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-771218.pdfVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.