The vendor explicitly identifies these products as affected by this CVE.
- Development/Evaluation Kits for PROFINET IO: DK Standard Ethernet Controller
- Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200
- Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200P
- IE/AS-i Link PN IO
- IE/PB-Link (incl. SIPLUS NET variants)
- SCALANCE M-800 family (incl. S615, MUM-800 and RM1224)
- SCALANCE W-700 IEEE 802.11n family
- SCALANCE X-200 family (incl. SIPLUS NET variants)
- SCALANCE X-200IRT family (incl. SIPLUS NET variants)
- SCALANCE X-300 family (incl. X408 and SIPLUS NET variants)
- SCALANCE X408 family
- SCALANCE X414
- Summary
- Specially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a denial of service condition of that product. Human interaction is required to recover the system. PROFIBUS interfaces are not affected.
- Remediation
- Update to V1.0.2 or later version
