The PROFINET (PNIO) stack, when integrated with the Interniche IP stack, improperly handles internal resources for TCP segments where the minimum TCP-Header length is less than defined.

This could allow an attacker to create a denial of service condition for TCP services on affected devices by sending specially crafted TCP segments.

Project Subscriptions

Vendors Products
Siemens Subscribe
Simatic Cfu Diq Subscribe
Simatic Cfu Diq Firmware Subscribe
Simatic Cfu Pa Subscribe
Simatic Cfu Pa Firmware Subscribe
Simatic S7-1500 Cpu Subscribe
Simatic S7-1500 Cpu Firmware Subscribe
Simatic S7-300 Cpu Subscribe
Simatic S7-300 Cpu Firmware Subscribe
Simatic S7-400 Pn\/dp V7 Subscribe
Simatic S7-400 Pn\/dp V7 Firmware Subscribe
Simatic S7-400h V6 Subscribe
Simatic S7-400h V6 Firmware Subscribe
Simatic S7-410 V10 Subscribe
Simatic S7-410 V10 Firmware Subscribe
Simatic S7-410 V8 Subscribe
Simatic S7-410 V8 Firmware Subscribe
Simatic Tdc Cp51m1 Subscribe
Simatic Tdc Cp51m1 Firmware Subscribe
Simatic Tdc Cpu555 Subscribe
Simatic Tdc Cpu555 Firmware Subscribe
Simatic Winac Rtx Subscribe
Simatic Winac Rtx Firmware Subscribe
Simit Simulation Platform Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2022-30282 The PROFINET (PNIO) stack, when integrated with the Interniche IP stack, improperly handles internal resources for TCP segments where the minimum TCP-Header length is less than defined. This could allow an attacker to create a denial of service condition for TCP services on affected devices by sending specially crafted TCP segments.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2025-04-21T13:54:36.799Z

Reserved: 2022-02-21T00:00:00.000Z

Link: CVE-2022-25622

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-04-12T09:15:14.483

Modified: 2024-11-21T06:52:27.700

Link: CVE-2022-25622

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses