A vulnerability has been identified in SIMATIC CP 1242-7 V2 (All versions < V3.3.46), SIMATIC CP 1243-1 (All versions < V3.3.46), SIMATIC CP 1243-7 LTE EU (All versions < V3.3.46), SIMATIC CP 1243-7 LTE US (All versions < V3.3.46), SIMATIC CP 1243-8 IRC (All versions < V3.3.46), SIMATIC CP 1542SP-1 IRC (All versions >= V2.0 < V2.2.28), SIMATIC CP 1543-1 (All versions < V3.0.22), SIMATIC CP 1543SP-1 (All versions >= V2.0 < V2.2.28), SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL (All versions >= V2.0 < V2.2.28), SIPLUS ET 200SP CP 1543SP-1 ISEC (All versions >= V2.0 < V2.2.28), SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL (All versions >= V2.0 < V2.2.28), SIPLUS NET CP 1242-7 V2 (All versions < V3.3.46), SIPLUS NET CP 1543-1 (All versions < V3.0.22), SIPLUS S7-1200 CP 1243-1 (All versions < V3.3.46), SIPLUS S7-1200 CP 1243-1 RAIL (All versions < V3.3.46). The application does not correctly escape some user provided fields during the authentication process. This could allow an attacker to inject custom commands and execute arbitrary code with elevated privileges.

Project Subscriptions

Vendors Products
Siemens Subscribe
Simatic Cp 1242-7 V2 Subscribe
Simatic Cp 1242-7 V2 Firmware Subscribe
Simatic Cp 1243-1 Subscribe
Simatic Cp 1243-1 Firmware Subscribe
Simatic Cp 1243-7 Lte Eu Subscribe
Simatic Cp 1243-7 Lte Eu Firmware Subscribe
Simatic Cp 1243-7 Lte Us Subscribe
Simatic Cp 1243-7 Lte Us Firmware Subscribe
Simatic Cp 1243-8 Irc Subscribe
Simatic Cp 1243-8 Irc Firmware Subscribe
Simatic Cp 1542sp-1 Irc Subscribe
Simatic Cp 1542sp-1 Irc Firmware Subscribe
Simatic Cp 1543-1 Subscribe
Simatic Cp 1543-1 Firmware Subscribe
Simatic Cp 1543sp-1 Subscribe
Simatic Cp 1543sp-1 Firmware Subscribe
Siplus Et 200sp Cp 1542sp-1 Irc Tx Rail Subscribe
Siplus Et 200sp Cp 1542sp-1 Irc Tx Rail Firmware Subscribe
Siplus Et 200sp Cp 1543sp-1 Isec Subscribe
Siplus Et 200sp Cp 1543sp-1 Isec Firmware Subscribe
Siplus Et 200sp Cp 1543sp-1 Isec Tx Rail Subscribe
Siplus Et 200sp Cp 1543sp-1 Isec Tx Rail Firmware Subscribe
Siplus Net Cp 1242-7 V2 Subscribe
Siplus Net Cp 1242-7 V2 Firmware Subscribe
Siplus Net Cp 1543-1 Subscribe
Siplus Net Cp 1543-1 Firmware Subscribe
Siplus S7-1200 Cp 1243-1 Subscribe
Siplus S7-1200 Cp 1243-1 Firmware Subscribe
Siplus S7-1200 Cp 1243-1 Rail Subscribe
Siplus S7-1200 Cp 1243-1 Rail Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2022-37726 A vulnerability has been identified in SIMATIC CP 1242-7 V2 (All versions < V3.3.46), SIMATIC CP 1243-1 (All versions < V3.3.46), SIMATIC CP 1243-7 LTE EU (All versions < V3.3.46), SIMATIC CP 1243-7 LTE US (All versions < V3.3.46), SIMATIC CP 1243-8 IRC (All versions < V3.3.46), SIMATIC CP 1542SP-1 IRC (All versions >= V2.0 < V2.2.28), SIMATIC CP 1543-1 (All versions < V3.0.22), SIMATIC CP 1543SP-1 (All versions >= V2.0 < V2.2.28), SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL (All versions >= V2.0 < V2.2.28), SIPLUS ET 200SP CP 1543SP-1 ISEC (All versions >= V2.0 < V2.2.28), SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL (All versions >= V2.0 < V2.2.28), SIPLUS NET CP 1242-7 V2 (All versions < V3.3.46), SIPLUS NET CP 1543-1 (All versions < V3.0.22), SIPLUS S7-1200 CP 1243-1 (All versions < V3.3.46), SIPLUS S7-1200 CP 1243-1 RAIL (All versions < V3.3.46). The application does not correctly escape some user provided fields during the authentication process. This could allow an attacker to inject custom commands and execute arbitrary code with elevated privileges.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00267}

epss

{'score': 0.00281}


Mon, 21 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2025-04-21T13:51:29.230Z

Reserved: 2022-06-29T00:00:00.000Z

Link: CVE-2022-34820

cve-icon Vulnrichment

Updated: 2024-08-03T09:22:10.675Z

cve-icon NVD

Status : Modified

Published: 2022-07-12T10:15:12.343

Modified: 2024-11-21T07:10:15.080

Link: CVE-2022-34820

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses