7/22/2014 4:46 PM | |
Posts: 1058 Rating:
|
Hello rvleugel, I hear about this problem the first time. You shouldforward that problem to Siemens. You can easily do so here. Click on support request there and describe the problem. Siemens will then work for a fix. regards |
7/23/2014 10:26 AM | |
Joined: 10/7/2005 Last visit: 3/24/2025 Posts: 3042 Rating:
|
Hello rvleugel not too sure how you managed to do a 256kb size package scan via S7-PCT (did you perhaps use Colasoft or something similar?), butcan tell you that any S7-1200 prior to FW V4.x had a few "Vulnerabilities" thatcan lead to a CPU crash as you eperienced. The officially security relatedS7-1200 "Vulnerabilities" are listed in the ICS-CERTAdvisory (ICSA-14-079-02)and Siemens own overview is available at http://www.siemens.com/innovation/en/technology-focus/siemens-cert/cert-security-advisories.htm. I'd certainly be interested to know if you can reproduce thisresult with a FW V4.x S7-1200, so please keep us posted. |
Cheers |
|
This contribution was helpful to
1 thankful Users |
7/23/2014 10:58 AM | |
Joined: 5/7/2009 Last visit: 12/6/2024 Posts: 7 Rating:
|
We keep you posted. To send 256kb packits just use in command prompt: ping "destiny ip" -i 256 -t I did read your link about the vurnabilities, and it looks like this problem:
IMPROPER RESOURCE SHUTDOWN OR RELEASEjAn attacker could cause the device to go into defect mode, effectively causing a DoS, if specially crafted PROFINET packets are sent to the device. A cold restart is required to recover the system. CVE-2014-2252khas been assigned to this vulnerability. A CVSS v2 base score of 6.1 has been assigned; the CVSS vector string is (AV:A/AC:L/Au:N/C:N/I:N/A:C).l |
Last edited by: rvleugel at: 7/23/2014 11:02 AM |
|
This contribution was helpful to
1 thankful Users |
Follow us on