Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2018-13815 Details

Description

A vulnerability has been identified in SIMATIC S7-1200 (All versions), SIMATIC S7-1500 (All Versions < V2.6). An attacker could exhaust the available connection pool of an affected device by opening a sufficient number of connections to the device. Successful exploitation requires an attacker to be able to send packets to port 102/tcp of the affected device. No user interaction and no user privileges are required to exploit the vulnerability. The vulnerability, if exploited, could cause a Denial-of-Service condition impacting the availability of the system. At the time of advisory publication no public exploitation of this vulnerability was known.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-400Uncontrolled Resource Consumption[email protected]
CWE-410Insufficient Resource Pool[email protected]

Affected Products

ProductVersions
siemens simatic s7-1200 firmware
All versions

CPE

  • cpe:2.3:o:siemens:simatic_s7-1200_firmware:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
siemens simatic s7-1200
All versions

CPE

  • cpe:2.3:h:siemens:simatic_s7-1200:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
siemens simatic s7-1500 firmware
< 2.6

CPE

  • cpe:2.3:o:siemens:simatic_s7-1500_firmware:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
siemens simatic s7-1500
All versions

CPE

  • cpe:2.3:h:siemens:simatic_s7-1500:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

6 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2018-13815
NVD Published Date:
Dec 13, 2018
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2018-13815 Details - Not Deferred