The vendor explicitly identifies these products as affected by this CVE.
- Opcenter Execution Foundation
- Opcenter Quality
- SIMATIC PCS neo
- SINEC NMS
- Totally Integrated Automation Portal (TIA Portal) V14
- Totally Integrated Automation Portal (TIA Portal) V15.1
- Totally Integrated Automation Portal (TIA Portal) V16
- Totally Integrated Automation Portal (TIA Portal) V17
- Totally Integrated Automation Portal (TIA Portal) V18
- Summary
- The affected application contains an improper input validation vulnerability that could allow an attacker to bring the service into a Denial-of-Service state by sending a specifically crafted message to 4004/tcp. The corresponding service is auto-restarted after the crash is detected by a watchdog.
- Remediation
- Update to V17 Update 8 or later version
