
CVE-2022-25622
https://notcve.org/view.php?id=CVE-2022-25622
12 Apr 2022 — The PROFINET (PNIO) stack, when integrated with the Interniche IP stack, improperly handles internal resources for TCP segments where the minimum TCP-Header length is less than defined. This could allow an attacker to create a denial of service condition for TCP services on affected devices by sending specially crafted TCP segments. Se ha identificado una vulnerabilidad en SIMATIC CFU DIQ, SIMATIC CFU PA, SIMATIC ET 200S IM151-8 PN/DP CPU, SIMATIC ET 200S IM151-8F PN/DP CPU, SIMATIC ET 200pro IM154-8 PN/DP ... • https://cert-portal.siemens.com/productcert/html/ssa-446448.html • CWE-400: Uncontrolled Resource Consumption •

CVE-2019-10936
https://notcve.org/view.php?id=CVE-2019-10936
10 Oct 2019 — Affected devices improperly handle large amounts of specially crafted UDP packets. This could allow an unauthenticated remote attacker to trigger a denial of service condition. Se ha identificado una vulnerabilidad en Development/Evaluation Kits for PROFINET IO: DK Standard Ethernet Controller, Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200, Kits de desarrollo/evaluación para PROFINET IO: EK-ERTEC 200P, SIMATIC CFU PA, SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. variantes SIPLUS), SIMAT... • https://cert-portal.siemens.com/productcert/html/ssa-473245.html • CWE-400: Uncontrolled Resource Consumption •

CVE-2016-2200
https://notcve.org/view.php?id=CVE-2016-2200
08 Feb 2016 — Siemens SIMATIC S7-1500 CPU devices before 1.8.3 allow remote attackers to cause a denial of service (STOP mode transition) via crafted packets on TCP port 102. Dispositivos Siemens SIMATIC S7-1500 CPU en versiones anteriores a 1.8.3 permiten a atacantes remotos causar una denegación de servicio (transición al modo STOP) a través de paquetes manipulados sobre el puerto 102 TCP. • http://www.securityfocus.com/bid/83106 • CWE-20: Improper Input Validation •

CVE-2014-5074 – Siemens SIMATIC S7-1500 CPU - Remote Denial of Service
https://notcve.org/view.php?id=CVE-2014-5074
17 Aug 2014 — Siemens SIMATIC S7-1500 CPU devices with firmware before 1.6 allow remote attackers to cause a denial of service (device restart and STOP transition) via crafted TCP packets. Los dispositivos Siemens SIMATIC S7-1500 CPU con firmware anterior a 1.6 permiten a atacantes remotos causar una denegación de servicio (reinicio de dispositivos y transición STOP) a través de paquetes TCP manipulados. • https://www.exploit-db.com/exploits/44693 •

CVE-2014-2253
https://notcve.org/view.php?id=CVE-2014-2253
16 Mar 2014 — Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allow remote attackers to cause a denial of service (defect-mode transition) via crafted Profinet packets. Dispositivos de Siemens SIMATIC S7-1500 CPU PLC con firmware anterior a 1.5.0 permiten a atacantes remotos causar una denegación de servicio (transición de modo defecto) a través de paquetes Profinet manipulados. • http://ics-cert.us-cert.gov/advisories/ICSA-14-073-01 •

CVE-2014-2247
https://notcve.org/view.php?id=CVE-2014-2247
16 Mar 2014 — The integrated web server on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allows remote attackers to inject headers via unspecified vectors. El servidor web integrado en dispositivos Siemens SIMATIC S7-1500 CPU PLC con firmware anterior a 1.5.0 permite a atacantes remotos inyectar cabeceras a través de vectores no especificados. • http://ics-cert.us-cert.gov/advisories/ICSA-14-073-01 •

CVE-2014-2259
https://notcve.org/view.php?id=CVE-2014-2259
16 Mar 2014 — Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allow remote attackers to cause a denial of service (defect-mode transition) via crafted HTTPS packets. Dispositivos de Siemens SIMATIC S7-1500 CPU PLC con firmware anterior a 1.5.0 permiten a atacantes remotos causar una denegación de servicio (transición de modo defecto) a través de paquetes HTTPS manipulados. • http://ics-cert.us-cert.gov/advisories/ICSA-14-073-01 •

CVE-2014-2249
https://notcve.org/view.php?id=CVE-2014-2249
16 Mar 2014 — Cross-site request forgery (CSRF) vulnerability on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 and SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. Una vulnerabilidad de tipo cross-site request forgery (CSRF) en dispositivos SIMATIC S7-1500 CPU PLC de Siemens con versión de firmware anterior a 1.5.0 y dispositivos SIMATIC S7-1200 CPU PLC con versión de firmware anterior a 4.0 de Si... • http://ics-cert.us-cert.gov/advisories/ICSA-14-073-01 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2014-2255
https://notcve.org/view.php?id=CVE-2014-2255
16 Mar 2014 — Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allow remote attackers to cause a denial of service (defect-mode transition) via crafted HTTP packets. Dispositivos de Siemens SIMATIC S7-1500 CPU PLC con firmware anterior a 1.5.0 permiten a atacantes remotos causar una denegación de servicio (transición de modo defecto) a través de paquetes HTTP manipulados. • http://ics-cert.us-cert.gov/advisories/ICSA-14-073-01 •

CVE-2014-2257
https://notcve.org/view.php?id=CVE-2014-2257
16 Mar 2014 — Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allow remote attackers to cause a denial of service (defect-mode transition) via crafted ISO-TSAP packets. Dispositivos de Siemens SIMATIC S7-1500 CPU PLC con firmware anterior a 1.5.0 permiten a atacantes remotos causar una denegación de servicio (transición de modo defecto) a través de paquetes ISO-TSAP manipulados. • http://ics-cert.us-cert.gov/advisories/ICSA-14-073-01 •