CVE-2022-31810
published 2023-07-11CVE-2022-31810: A vulnerability has been identified in SiPass integrated (All versions < V2.90.3.8). Affected server applications improperly check the size of data packets…
PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.88%
54.9th percentile
A vulnerability has been identified in SiPass integrated (All versions < V2.90.3.8). Affected server applications improperly check the size of data packets received for the configuration client login, causing a stack-based buffer overflow.
This could allow an unauthenticated remote attacker to crash the server application, creating a denial of service condition.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | sipass_integrated | < 2.90.3.8 | 2.90.3.8 |
| siemens | sipass_integrated | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fm23-rwc2-2p82: A vulnerability has been identified in SiPass integrated (All versions < V2
ghsa_unreviewed·2023-07-11
CVE-2022-31810 [HIGH] CWE-20 GHSA-fm23-rwc2-2p82: A vulnerability has been identified in SiPass integrated (All versions < V2
A vulnerability has been identified in SiPass integrated (All versions < V2.90.3.8). Affected server applications improperly check the size of data packets received for the configuration client login, causing a stack-based buffer overflow.
This could allow an unauthenticated remote attacker to crash the server application, creating a denial of service condition.
CISA ICS
Siemens SiPass Integrated
cisa_ics·2023-07-13·CVSS 7.5
[HIGH] Siemens SiPass Integrated
ICS Advisory
##
Siemens SiPass Integrated
Release DateJuly 13, 2023
Alert CodeICSA-23-194-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely / low attack complexity
- Vendor: Siemens
- Equipment: SiPass Integrated
- Vulnerability: Improper Input Validation
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to crash the server application, creating a denial-of-service condition.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Siemens reports this vulnerability affects the following SiPass integrated products:
- SiPass integrated: all versions prior to V2.90.3.8
## 3.2 VULNERABILITY OVERVIEW
3.2.1 IMPROPER INPUT VALIDATION CWE-20
Affected server applica
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-07-11
Published