The vendor explicitly identifies these products as affected by this CVE.
- SIMATIC PC-Station Plus
- SIMATIC S7-400 CPU 412-2 PN V7 (6ES7412-2EK07-0AB0)
- SIMATIC S7-400 CPU 414-3 PN/DP V7 (6ES7414-3EM07-0AB0)
- SIMATIC S7-400 CPU 414F-3 PN/DP V7 (6ES7414-3FM07-0AB0)
- SIMATIC S7-400 CPU 416-3 PN/DP V7 (6ES7416-3ES07-0AB0)
- SIMATIC S7-400 CPU 416F-3 PN/DP V7 (6ES7416-3FS07-0AB0)
- SINAMICS S120 (incl. SIPLUS variants)
- SIPLUS S7-400 CPU 414-3 PN/DP V7 (6AG1414-3EM07-7AB0)
- SIPLUS S7-400 CPU 416-3 PN/DP V7 (6AG1416-3ES07-7AB0)
- Summary
- The affected products do not handle long file names correctly. This could allow an attacker to create a buffer overflow and create a denial of service condition for the device.
- Remediation
- Update to V5.2 SP3 HF15 or later version
