CVE-2022-25622
published 2022-04-12CVE-2022-25622: The PROFINET (PNIO) stack, when integrated with the Interniche IP stack, improperly handles internal resources for TCP segments where the minimum TCP-Header…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.85%
54.0th percentile
The PROFINET (PNIO) stack, when integrated with the Interniche IP stack, improperly handles internal resources for TCP segments where the minimum TCP-Header length is less than defined.
This could allow an attacker to create a denial of service condition for TCP services on affected devices by sending specially crafted TCP segments.
Affected
69 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | simatic_cfu_diq | < V2.0.0 | V2.0.0 |
| siemens | simatic_cfu_pa | < V2.0.0 | V2.0.0 |
| siemens | simatic_et_200al_im_157-1_pn | — | — |
| siemens | simatic_et_200mp_im_155-5_pn_hf | >= V4.2.0 < * | * |
| siemens | simatic_et_200pro_im_154-8_pn_dp_cpu | — | — |
| siemens | simatic_et_200pro_im_154-8f_pn_dp_cpu | — | — |
| siemens | simatic_et_200pro_im_154-8fx_pn_dp_cpu | — | — |
| siemens | simatic_et_200s_im_151-8_pn_dp_cpu | — | — |
| siemens | simatic_et_200s_im_151-8f_pn_dp_cpu | — | — |
| siemens | simatic_et_200sp_im_155-6_mf_hf | < * | * |
| siemens | simatic_et_200sp_im_155-6_pn_2_hf | >= V4.2.0 < * | * |
| siemens | simatic_et_200sp_im_155-6_pn_3_hf | >= V4.2.0 < * | * |
| siemens | simatic_et_200sp_im_155-6_pn_ha | — | — |
| siemens | simatic_et_200sp_im_155-6_pn_hf | >= V4.2.0 < * | * |
| siemens | simatic_pn_mf_coupler | — | — |
| siemens | simatic_pn_pn_coupler | — | — |
| siemens | simatic_s7-1500_cpu_family | — | — |
| siemens | simatic_s7-1500_cpu_firmware | < 2.0.0 | 2.0.0 |
| siemens | simatic_s7-300_cpu_314c-2_pn_dp | — | — |
| siemens | simatic_s7-300_cpu_315-2_pn_dp | — | — |
| siemens | simatic_s7-300_cpu_315f-2_pn_dp | — | — |
| siemens | simatic_s7-300_cpu_315t-3_pn_dp | — | — |
| siemens | simatic_s7-300_cpu_317-2_pn_dp | — | — |
| siemens | simatic_s7-300_cpu_317f-2_pn_dp | — | — |
| siemens | simatic_s7-300_cpu_317t-3_pn_dp | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pgxc-2q22-7c2f: A vulnerability has been identified in SIMATIC CFU DIQ (All versions), SIMATIC CFU PA (All versions), SIMATIC S7-1500 CPU family (incl
ghsa_unreviewed·2022-04-13
CVE-2022-25622 [HIGH] CWE-400 GHSA-pgxc-2q22-7c2f: A vulnerability has been identified in SIMATIC CFU DIQ (All versions), SIMATIC CFU PA (All versions), SIMATIC S7-1500 CPU family (incl
A vulnerability has been identified in SIMATIC CFU DIQ (All versions), SIMATIC CFU PA (All versions), SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions < V2.0.0), SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC S7-400 H V6 CPU family (incl. SIPLUS variants) (All versions < V6.0.10), SIMATIC S7-400 PN/DP V7 CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-410 V10 CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-410 V8 CPU family (incl. SIPLUS variants) (All versions), SIMATIC TDC CP51M1 (All versions), SIMATIC TDC CPU555 (All versions), SIMATIC WinAC RTX (All versions), SIMIT Simulation Platform (All versions). The PROFINET (PNIO) stack, when integrated with the Interniche IP sta
CISA ICS
Siemens PROFINET Stack Integrated on Interniche Stack (Update E)
cisa_ics·2022-10-13
Siemens PROFINET Stack Integrated on Interniche Stack (Update E)
ICS Advisory
##
Siemens PROFINET Stack Integrated on Interniche Stack (Update E)
Last RevisedJanuary 13, 2023
Alert CodeICSA-22-104-06
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 5.3
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: PROFINET Stack Integrated on Interniche Stack
- Vulnerability: Uncontrolled Resource Consumption
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the original advisory titled IC
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-04-12
Published