CVE-2021-33737
A vulnerability has been identified in SIMATIC CP 343-1 (incl. SIPLUS variants) (All versions), SIMATIC CP 343-1 Advanced (incl. SIPLUS variants) (All versions), SIMATIC CP 343-1 ERPC (All versions), SIMATIC CP 343-1 Lean (incl. SIPLUS variants) (All versions), SIMATIC CP 443-1 (All versions < V3.3), SIMATIC CP 443-1 (All versions < V3.3), SIMATIC CP 443-1 Advanced (All versions < V3.3), SIPLUS NET CP 443-1 (All versions < V3.3), SIPLUS NET CP 443-1 Advanced (All versions < V3.3). Sending a specially crafted packet to port 102/tcp of an affected device could cause a denial of service condition. A restart is needed to restore normal operations.
EPSS 0.15% · 35.8th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | SIMATIC CP 443-1 | All versions < V3.3, * |
| Siemens | SIMATIC CP 343-1 (incl. SIPLUS variants) | All versions |
| siemens | simatic_cp_343-1_erpc_firmware | |
| siemens | simatic_cp_343-1_advanced_firmware | |
| Siemens | SIMATIC CP 343-1 Advanced (incl. SIPLUS variants) | * |
| siemens | simatic_cp_443-1_advanced_firmware | |
| siemens | simatic_cp_443-1_firmware | |
| Siemens | SIPLUS NET CP 443-1 Advanced | All versions < V3.3 |
| siemens | simatic_cp_343-1_firmware | |
| Siemens | SIMATIC CP 343-1 ERPC | * |
| siemens | simatic_cp_343-1_lean_firmware | |
| Siemens | SIMATIC CP 343-1 Lean (incl. SIPLUS variants) | All versions |
| Siemens | SIPLUS NET CP 443-1 | All versions < V3.3 |
| Siemens | SIMATIC CP 443-1 Advanced | * |
Exploit Intelligence
- This proof-of-concept script exploits a vulnerability in OpenSSH versions prior to 7.4 (CVE-2016-10708) by sending unexpected `SSH_MSG_NEWKEYS` packets. (github-poc)
- This proof-of-concept script exploits a vulnerability in OpenSSH versions prior to 7.4 (CVE-2016-10708) by sending unexpected `SSH_MSG_NEWKEYS` packets. (github-poc)
- This proof-of-concept script exploits a vulnerability in OpenSSH versions prior to 7.4 (CVE-2016-10708) by sending unexpected `SSH_MSG_NEWKEYS` packets. (github-poc)
- This proof-of-concept script exploits a vulnerability in OpenSSH versions prior to 7.4 (CVE-2016-10708) by sending unexpected `SSH_MSG_NEWKEYS` packets. (github-poc)
- This proof-of-concept script exploits a vulnerability in OpenSSH versions prior to 7.4 (CVE-2016-10708) by sending unexpected `SSH_MSG_NEWKEYS` packets. (github-poc)
- https://cert-portal.siemens.com/productcert/pdf/ssa-549234.pdf (circl)
Timeline
- Apr 13, 2021 CVE Published
- Sep 15, 2021 EPSS Score
- Oct 5, 2021 EPSS Score
- Oct 11, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Jan 8, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 6, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Jun 29, 2022 EPSS Score
- Aug 27, 2022 EPSS Score
- Oct 23, 2022 EPSS Score
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-847986.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-549234.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-208530.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-288459.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-987403.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-535380.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-334944.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-676336.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-997732.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-835377.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-109294.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-453715.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-692317.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-756638.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-316383.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-330339.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-500748.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-535997.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-150692.pdf advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-413407.pdf advisory
…and 2 more