Executive brief
Siemens SIMATIC ET 200 interface modules and network couplers, which are used to connect industrial field devices to controllers, are vulnerable to a denial-of-service attack. An attacker can send a specific network command that causes the device to freeze and become completely unresponsive. This would disrupt industrial operations and requires a physical power cycle (restarting the hardware) to restore service.
Technical details
A vulnerability in the S7 protocol handling of several Siemens SIMATIC ET 200 and PN/PN coupler devices allows for a remote denial-of-service. The issue is caused by improper state management when the device receives a valid S7 protocol Disconnect Request (COTP DR TPDU) on TCP port 102. An unauthenticated attacker can trigger this by sending a specially crafted disconnect request, causing the device to enter an improper session state and become unresponsive. Recovery requires a manual power cycle. Siemens has released firmware updates for several affected models (e.g., ET 200SP IM 155-6 PN HA V1.3, PN/PN Coupler V6.0.0), while others currently have no planned fix and rely on network-level mitigations like port filtering.
Affected products
- Siemens SIMATIC ET 200AL IM 157-1 PN All versions
- Siemens SIMATIC ET 200MP IM 155-5 PN HF All versions >= V4.2.0
- Siemens SIMATIC ET 200SP IM 155-6 MF HF All versions
- Siemens SIMATIC ET 200SP IM 155-6 PN HA All versions < V1.3
- Siemens SIMATIC ET 200SP IM 155-6 PN R1 All versions < V6.0.1
- Siemens SIMATIC ET 200SP IM 155-6 PN/2 HF All versions >= V4.2.0 < V4.2.5
- Siemens SIMATIC ET 200SP IM 155-6 PN/3 HF All versions < V4.2.2
- Siemens SIMATIC PN/MF Coupler All versions
- Siemens SIMATIC PN/PN Coupler All versions < V6.0.0
Timeline
- 2026-01-13: advisory: Initial publication by Siemens ProductCERT
- 2026-06-09: patched: Updated advisory with additional fixes for SIMATIC ET 200SP variants