Description
The PROFINET (PNIO) stack, when integrated with the Interniche IP stack, improperly handles internal resources for TCP segments where the minimum TCP-Header length is less than defined.

This could allow an attacker to create a denial of service condition for TCP services on affected devices by sending specially crafted TCP segments.
Published: 2022-04-12
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-30282 The PROFINET (PNIO) stack, when integrated with the Interniche IP stack, improperly handles internal resources for TCP segments where the minimum TCP-Header length is less than defined. This could allow an attacker to create a denial of service condition for TCP services on affected devices by sending specially crafted TCP segments.
History

No history.

Subscriptions

Siemens Simatic Cfu Diq Simatic Cfu Diq Firmware Simatic Cfu Pa Simatic Cfu Pa Firmware Simatic S7-1500 Cpu Simatic S7-1500 Cpu Firmware Simatic S7-300 Cpu Simatic S7-300 Cpu Firmware Simatic S7-400 Pn\/dp V7 Simatic S7-400 Pn\/dp V7 Firmware Simatic S7-400h V6 Simatic S7-400h V6 Firmware Simatic S7-410 V10 Simatic S7-410 V10 Firmware Simatic S7-410 V8 Simatic S7-410 V8 Firmware Simatic Tdc Cp51m1 Simatic Tdc Cp51m1 Firmware Simatic Tdc Cpu555 Simatic Tdc Cpu555 Firmware Simatic Winac Rtx Simatic Winac Rtx Firmware Simit Simulation Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2025-04-21T13:54:36.799Z

Reserved: 2022-02-21T00:00:00.000Z

Link: CVE-2022-25622

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-04-12T09:15:14.483

Modified: 2024-11-21T06:52:27.700

Link: CVE-2022-25622

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses