CVE-2022-25622
12.04.2022, 09:15
The PROFINET (PNIO) stack, when integrated with the Interniche IP stack, improperly handles internal resources for TCP segments where the minimum TCP-Header length is less than defined. This could allow an attacker to create a denial of service condition for TCP services on affected devices by sending specially crafted TCP segments.Enginsight
Vendor | Product | Version |
---|---|---|
siemens | simatic_cfu_diq_firmware | * |
siemens | simatic_cfu_pa_firmware | * |
siemens | simatic_s7-300_cpu_firmware | * |
siemens | simatic_s7-400h_v6_firmware | * |
siemens | simatic_s7-400_pn\/dp_v7_firmware | * |
siemens | simatic_s7-410_v8_firmware | * |
siemens | simatic_s7-410_v10_firmware | * |
siemens | simatic_s7-1500_cpu_firmware | 𝑥 < 2.0.0 |
siemens | simatic_tdc_cp51m1_firmware | * |
siemens | simatic_tdc_cpu555_firmware | * |
siemens | simatic_winac_rtx_firmware | * |
siemens | simit_simulation_platform | * |
𝑥
= Vulnerable software versions