CVE-2022-42784

A vulnerability has been identified in LOGO! 12/24RCE (All versions >= V8.3), LOGO! 12/24RCEo (All versions >= V8.3), LOGO! 230RCE (All versions >= V8.3), LOGO! 230RCEo (All versions >= V8.3), LOGO! 24CE (All versions >= V8.3), LOGO! 24CEo (All versions >= V8.3), LOGO! 24RCE (All versions >= V8.3), LOGO! 24RCEo (All versions >= V8.3), SIPLUS LOGO! 12/24RCE (All versions >= V8.3), SIPLUS LOGO! 12/24RCEo (All versions >= V8.3), SIPLUS LOGO! 230RCE (All versions >= V8.3), SIPLUS LOGO! 230RCEo (All versions >= V8.3), SIPLUS LOGO! 24CE (All versions >= V8.3), SIPLUS LOGO! 24CEo (All versions >= V8.3), SIPLUS LOGO! 24RCE (All versions >= V8.3), SIPLUS LOGO! 24RCEo (All versions >= V8.3). Affected devices are vulnerable to an electromagnetic fault injection. This could allow an attacker to dump and debug the firmware, including the manipulation of memory. Further actions could allow to inject public keys of custom created key pairs which are then signed by the product CA. The generation of a custom certificate allows communication with, and impersonation of, any device of the same version.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:h:siemens:6ed1052-1md08-0ba1:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:6ed1052-1md08-0ba1_firmware:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:h:siemens:6ed1052-2md08-0ba1:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:6ed1052-2md08-0ba1_firmware:*:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:h:siemens:6ed1052-1cc08-0ba1:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:6ed1052-1cc08-0ba1_firmware:*:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:h:siemens:6ed1052-2cc08-0ba1:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:6ed1052-2cc08-0ba1_firmware:*:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:siemens:6ed1052-1hb08-0ba1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:6ed1052-1hb08-0ba1:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:siemens:6ed1052-2hb08-0ba1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:6ed1052-2hb08-0ba1:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:siemens:6ed1052-1fb08-0ba1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:6ed1052-1fb08-0ba1:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:siemens:6ed1052-2fb08-0ba1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:6ed1052-2fb08-0ba1:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:siemens:6ag1052-1md08-7ba1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:6ag1052-1md08-7ba1:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:siemens:6ag1052-2md08-7ba1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:6ag1052-2md08-7ba1:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:siemens:6ag1052-1cc08-7ba1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:6ag1052-1cc08-7ba1:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:siemens:6ag1052-2cc08-7ba1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:6ag1052-2cc08-7ba1:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:siemens:6ag1052-1hb08-7ba1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:6ag1052-1hb08-7ba1:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:siemens:6ag1052-2hb08-7ba1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:6ag1052-2hb08-7ba1:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:siemens:6ag1052-1fb08-7ba1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:6ag1052-1fb08-7ba1:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:siemens:6ag1052-2fb08-7ba1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:6ag1052-2fb08-7ba1:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-12-12 10:15

Updated : 2023-12-18 14:51


NVD link : CVE-2022-42784

Mitre link : CVE-2022-42784

CVE.ORG link : CVE-2022-42784


JSON object : View

Products Affected

siemens

  • 6ed1052-1fb08-0ba1
  • 6ed1052-1hb08-0ba1
  • 6ag1052-1hb08-7ba1
  • 6ed1052-2md08-0ba1_firmware
  • 6ed1052-1fb08-0ba1_firmware
  • 6ag1052-2fb08-7ba1
  • 6ag1052-2cc08-7ba1_firmware
  • 6ag1052-1hb08-7ba1_firmware
  • 6ed1052-1cc08-0ba1_firmware
  • 6ag1052-2hb08-7ba1
  • 6ag1052-2md08-7ba1
  • 6ag1052-1md08-7ba1_firmware
  • 6ed1052-2hb08-0ba1_firmware
  • 6ed1052-1hb08-0ba1_firmware
  • 6ag1052-2hb08-7ba1_firmware
  • 6ag1052-2fb08-7ba1_firmware
  • 6ed1052-2fb08-0ba1
  • 6ag1052-1md08-7ba1
  • 6ed1052-2cc08-0ba1_firmware
  • 6ag1052-1cc08-7ba1
  • 6ed1052-2cc08-0ba1
  • 6ag1052-1fb08-7ba1_firmware
  • 6ed1052-2fb08-0ba1_firmware
  • 6ed1052-2md08-0ba1
  • 6ag1052-2cc08-7ba1
  • 6ed1052-1md08-0ba1_firmware
  • 6ed1052-2hb08-0ba1
  • 6ag1052-2md08-7ba1_firmware
  • 6ed1052-1md08-0ba1
  • 6ag1052-1cc08-7ba1_firmware
  • 6ed1052-1cc08-0ba1
  • 6ag1052-1fb08-7ba1
CWE
NVD-CWE-Other CWE-1319

Improper Protection against Electromagnetic Fault Injection (EM-FI)