A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V17 Update 4), SIMATIC HMI KTP Mobile Panels (All versions < V17 Update 4), SIMATIC HMI KTP1200 Basic (All versions < V17 Update 5), SIMATIC HMI KTP400 Basic (All versions < V17 Update 5), SIMATIC HMI KTP700 Basic (All versions < V17 Update 5), SIMATIC HMI KTP900 Basic (All versions < V17 Update 5), SIPLUS HMI KTP1200 BASIC (All versions < V17 Update 5), SIPLUS HMI KTP400 BASIC (All versions < V17 Update 5), SIPLUS HMI KTP700 BASIC (All versions < V17 Update 5), SIPLUS HMI KTP900 BASIC (All versions < V17 Update 5). Affected devices do not properly validate input sent to certain services over TCP. This could allow an unauthenticated remote attacker to cause a permanent denial of service condition (requiring a device reboot) by sending specially crafted TCP packets.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Siemens
Subscribe
|
Simatic Hmi Comfort Panels
Subscribe
Simatic Hmi Comfort Panels Firmware
Subscribe
Simatic Hmi Ktp1200 Basic
Subscribe
Simatic Hmi Ktp1200 Basic Firmware
Subscribe
Simatic Hmi Ktp400 Basic
Subscribe
Simatic Hmi Ktp400 Basic Firmware
Subscribe
Simatic Hmi Ktp700 Basic
Subscribe
Simatic Hmi Ktp700 Basic Firmware
Subscribe
Simatic Hmi Ktp900 Basic
Subscribe
Simatic Hmi Ktp900 Basic Firmware
Subscribe
Simatic Hmi Ktp Mobile Panels
Subscribe
Simatic Hmi Ktp Mobile Panels Firmware
Subscribe
Siplus Hmi Ktp1200 Basic
Subscribe
Siplus Hmi Ktp1200 Basic Firmware
Subscribe
Siplus Hmi Ktp400 Basic
Subscribe
Siplus Hmi Ktp400 Basic Firmware
Subscribe
Siplus Hmi Ktp700 Basic
Subscribe
Siplus Hmi Ktp700 Basic Firmware
Subscribe
Siplus Hmi Ktp900 Basic
Subscribe
Siplus Hmi Ktp900 Basic Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-43525 | A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V17 Update 4), SIMATIC HMI KTP Mobile Panels (All versions < V17 Update 4), SIMATIC HMI KTP1200 Basic (All versions < V17 Update 5), SIMATIC HMI KTP400 Basic (All versions < V17 Update 5), SIMATIC HMI KTP700 Basic (All versions < V17 Update 5), SIMATIC HMI KTP900 Basic (All versions < V17 Update 5), SIPLUS HMI KTP1200 BASIC (All versions < V17 Update 5), SIPLUS HMI KTP400 BASIC (All versions < V17 Update 5), SIPLUS HMI KTP700 BASIC (All versions < V17 Update 5), SIPLUS HMI KTP900 BASIC (All versions < V17 Update 5). Affected devices do not properly validate input sent to certain services over TCP. This could allow an unauthenticated remote attacker to cause a permanent denial of service condition (requiring a device reboot) by sending specially crafted TCP packets. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: siemens
Published:
Updated: 2024-08-03T12:14:39.944Z
Reserved: 2022-09-08T00:00:00
Link: CVE-2022-40227
No data.
Status : Modified
Published: 2022-10-11T11:15:10.940
Modified: 2024-11-21T07:21:06.620
Link: CVE-2022-40227
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD