Description
A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V17 Update 4), SIMATIC HMI KTP Mobile Panels (All versions < V17 Update 4), SIMATIC HMI KTP1200 Basic (All versions < V17 Update 5), SIMATIC HMI KTP400 Basic (All versions < V17 Update 5), SIMATIC HMI KTP700 Basic (All versions < V17 Update 5), SIMATIC HMI KTP900 Basic (All versions < V17 Update 5), SIPLUS HMI KTP1200 BASIC (All versions < V17 Update 5), SIPLUS HMI KTP400 BASIC (All versions < V17 Update 5), SIPLUS HMI KTP700 BASIC (All versions < V17 Update 5), SIPLUS HMI KTP900 BASIC (All versions < V17 Update 5). Affected devices do not properly validate input sent to certain services over TCP. This could allow an unauthenticated remote attacker to cause a permanent denial of service condition (requiring a device reboot) by sending specially crafted TCP packets.
Published: 2022-10-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-43525 A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V17 Update 4), SIMATIC HMI KTP Mobile Panels (All versions < V17 Update 4), SIMATIC HMI KTP1200 Basic (All versions < V17 Update 5), SIMATIC HMI KTP400 Basic (All versions < V17 Update 5), SIMATIC HMI KTP700 Basic (All versions < V17 Update 5), SIMATIC HMI KTP900 Basic (All versions < V17 Update 5), SIPLUS HMI KTP1200 BASIC (All versions < V17 Update 5), SIPLUS HMI KTP400 BASIC (All versions < V17 Update 5), SIPLUS HMI KTP700 BASIC (All versions < V17 Update 5), SIPLUS HMI KTP900 BASIC (All versions < V17 Update 5). Affected devices do not properly validate input sent to certain services over TCP. This could allow an unauthenticated remote attacker to cause a permanent denial of service condition (requiring a device reboot) by sending specially crafted TCP packets.
History

No history.

Subscriptions

Siemens Simatic Hmi Comfort Panels Simatic Hmi Comfort Panels Firmware Simatic Hmi Ktp1200 Basic Simatic Hmi Ktp1200 Basic Firmware Simatic Hmi Ktp400 Basic Simatic Hmi Ktp400 Basic Firmware Simatic Hmi Ktp700 Basic Simatic Hmi Ktp700 Basic Firmware Simatic Hmi Ktp900 Basic Simatic Hmi Ktp900 Basic Firmware Simatic Hmi Ktp Mobile Panels Simatic Hmi Ktp Mobile Panels Firmware Siplus Hmi Ktp1200 Basic Siplus Hmi Ktp1200 Basic Firmware Siplus Hmi Ktp400 Basic Siplus Hmi Ktp400 Basic Firmware Siplus Hmi Ktp700 Basic Siplus Hmi Ktp700 Basic Firmware Siplus Hmi Ktp900 Basic Siplus Hmi Ktp900 Basic Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2024-08-03T12:14:39.944Z

Reserved: 2022-09-08T00:00:00.000Z

Link: CVE-2022-40227

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-10-11T11:15:10.940

Modified: 2024-11-21T07:21:06.620

Link: CVE-2022-40227

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses