CVE-2022-25622

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
12/04/2022
Last modified:
09/07/2024

Description

The PROFINET (PNIO) stack, when integrated with the Interniche IP stack, improperly handles internal resources for TCP segments where the minimum TCP-Header length is less than defined.<br /> <br /> This could allow an attacker to create a denial of service condition for TCP services on affected devices by sending specially crafted TCP segments.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:siemens:simatic_cfu_diq_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_cfu_diq:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_cfu_pa_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_cfu_pa:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_s7-300_cpu_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_s7-300_cpu:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_s7-400h_v6_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_s7-400h_v6:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_s7-400_pn\/dp_v7_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_s7-400_pn\/dp_v7:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_s7-410_v8_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_s7-410_v8:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_s7-410_v10_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_s7-410_v10:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_s7-1500_cpu_firmware:*:*:*:*:*:*:*:* 2.0.0 (excluding)