CVE-2022-25622
Severity CVSS v4.0:
Pending analysis
Type:
CWE-400
Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
12/04/2022
Last modified:
09/07/2024
Description
The PROFINET (PNIO) stack, when integrated with the Interniche IP stack, improperly handles internal resources for TCP segments where the minimum TCP-Header length is less than defined.<br />
<br />
This could allow an attacker to create a denial of service condition for TCP services on affected devices by sending specially crafted TCP segments.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:siemens:simatic_cfu_diq_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:siemens:simatic_cfu_diq:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:simatic_cfu_pa_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:siemens:simatic_cfu_pa:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:simatic_s7-300_cpu_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:siemens:simatic_s7-300_cpu:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:simatic_s7-400h_v6_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:siemens:simatic_s7-400h_v6:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:simatic_s7-400_pn\/dp_v7_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:siemens:simatic_s7-400_pn\/dp_v7:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:simatic_s7-410_v8_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:siemens:simatic_s7-410_v8:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:simatic_s7-410_v10_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:siemens:simatic_s7-410_v10:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:simatic_s7-1500_cpu_firmware:*:*:*:*:*:*:*:* | 2.0.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



