CVE-2022-25622

The PROFINET (PNIO) stack, when integrated with the Interniche IP stack, improperly handles internal resources for TCP segments where the minimum TCP-Header length is less than defined. This could allow an attacker to create a denial of service condition for TCP services on affected devices by sending specially crafted TCP segments.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:siemens:simatic_cfu_diq_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_cfu_diq:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:siemens:simatic_cfu_pa_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_cfu_pa:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:siemens:simatic_s7-300_cpu_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_s7-300_cpu:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:siemens:simatic_s7-400h_v6_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_s7-400h_v6:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:siemens:simatic_s7-400_pn\/dp_v7_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_s7-400_pn\/dp_v7:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:siemens:simatic_s7-410_v8_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_s7-410_v8:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:siemens:simatic_s7-410_v10_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_s7-410_v10:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:siemens:simatic_s7-1500_cpu_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_s7-1500_cpu:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:siemens:simatic_tdc_cp51m1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_tdc_cp51m1:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:siemens:simatic_tdc_cpu555_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_tdc_cpu555:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:siemens:simatic_winac_rtx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_winac_rtx:-:*:*:*:*:*:*:*

Configuration 12 (hide)

cpe:2.3:a:siemens:simit_simulation_platform:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-04-12 09:15

Updated : 2024-07-09 12:15


NVD link : CVE-2022-25622

Mitre link : CVE-2022-25622

CVE.ORG link : CVE-2022-25622


JSON object : View

Products Affected

siemens

  • simatic_s7-300_cpu_firmware
  • simatic_s7-1500_cpu_firmware
  • simatic_s7-410_v10_firmware
  • simatic_tdc_cp51m1_firmware
  • simatic_s7-410_v10
  • simatic_s7-410_v8
  • simatic_cfu_pa
  • simatic_tdc_cpu555_firmware
  • simatic_s7-410_v8_firmware
  • simatic_tdc_cp51m1
  • simatic_cfu_diq_firmware
  • simatic_s7-400h_v6
  • simatic_s7-400_pn\/dp_v7_firmware
  • simatic_s7-400_pn\/dp_v7
  • simatic_cfu_diq
  • simatic_winac_rtx_firmware
  • simatic_cfu_pa_firmware
  • simit_simulation_platform
  • simatic_winac_rtx
  • simatic_s7-1500_cpu
  • simatic_s7-300_cpu
  • simatic_s7-400h_v6_firmware
  • simatic_tdc_cpu555
CWE
CWE-400

Uncontrolled Resource Consumption