CVE-2018-13815
Description
A vulnerability has been identified in SIMATIC S7-1200 (All versions), SIMATIC S7-1500 (All Versions < V2.6). An attacker could exhaust the available connection pool of an affected device by opening a sufficient number of connections to the device. Successful exploitation requires an attacker to be able to send packets to port 102/tcp of the affected device. No user interaction and no user privileges are required to exploit the vulnerability. The vulnerability, if exploited, could cause a Denial-of-Service condition impacting the availability of the system. At the time of advisory publication no public exploitation of this vulnerability was known.
EPSS (Exploit Prediction Scoring System)
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score Trend (Last 91 Days)
Uncontrolled Resource Consumption
DraftCommon Consequences
Applicable Platforms
Insufficient Resource Pool
IncompleteCommon Consequences
Applicable Platforms
Simatic S7-1200 Firmware by Siemens
cpe:2.3:o:siemens:simatic_s7-1200_firmware:-:*:*:*:*:*:*:*
Simatic S7-1500 Firmware by Siemens
cpe:2.3:o:siemens:simatic_s7-1500_firmware:*:*:*:*:*:*:*:*