CVE-2022-40227
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V17 Update 4), SIMATIC HMI KTP Mobile Panels (All versions < V17 Update 4), SIMATIC HMI KTP1200 Basic (All versions < V17 Update 5), SIMATIC HMI KTP400 Basic (All versions < V17 Update 5), SIMATIC HMI KTP700 Basic (All versions < V17 Update 5), SIMATIC HMI KTP900 Basic (All versions < V17 Update 5), SIPLUS HMI KTP1200 BASIC (All versions < V17 Update 5), SIPLUS HMI KTP400 BASIC (All versions < V17 Update 5), SIPLUS HMI KTP700 BASIC (All versions < V17 Update 5), SIPLUS HMI KTP900 BASIC (All versions < V17 Update 5). Affected devices do not properly validate input sent to certain services over TCP. This could allow an unauthenticated remote attacker to cause a permanent denial of service condition (requiring a device reboot) by sending specially crafted TCP packets.
Affected (58)
Products: Siemens: Simatic Hmi Comfort Panels Firmware, Simatic Hmi Ktp400 Basic Firmware, Simatic Hmi Ktp700 Basic Firmware, Simatic Hmi Ktp900 Basic Firmware, Simatic Hmi Ktp1200 Basic Firmware, Simatic Hmi Ktp Mobile Panels Firmware, Siplus Hmi Ktp400 Basic Firmware, Siplus Hmi Ktp700 Basic Firmware, Siplus Hmi Ktp900 Basic Firmware, Siplus Hmi Ktp1200 Basic Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 17.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Hmi Comfort Panels | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 17.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Hmi Ktp400 Basic | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 17.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Hmi Ktp700 Basic | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 17.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Hmi Ktp900 Basic | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 17.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Hmi Ktp1200 Basic | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 17.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Hmi Ktp Mobile Panels | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 17.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Siplus Hmi Ktp400 Basic | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 17.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Siplus Hmi Ktp700 Basic | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 17.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Siplus Hmi Ktp900 Basic | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 17.0 |
| Running on/with | Platform Versions |
|---|---|
Siemens Siplus Hmi Ktp1200 Basic | All versions |
References (2)
Source: productcert@siemens.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.