CVE-2022-38465
published 2022-10-11CVE-2022-38465: A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS…
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.22%
12.2th percentile
A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V21.9), SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (All versions < V4.5.0), SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions < V2.9.2), SIMATIC S7-1500 Software Controller (All versions < V21.9), SIMATIC S7-PLCSIM Advanced (All versions < V4.0), SINUMERIK MC (All versions < V6.21), SINUMERIK ONE (All versions < V6.21). Affected products protect the built-in global private key in a way that cannot be considered sufficient any longer. The key is used for the legacy protection of confidential configuration data and the legacy PG/PC and HMI communication.
This could allow attackers to discover the private key of a CPU product family by an offline attack against a single CPU of the family. Attackers could then use this knowledge to extract confidential configuration data from projects that are protected by that key or to perform attacks against legacy PG/PC and HMI communication.
Affected
53 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | simatic_drive_controller_cpu_1504d_tf_firmware | < 2.9.2 | 2.9.2 |
| siemens | simatic_drive_controller_cpu_1507d_tf_firmware | < 2.9.2 | 2.9.2 |
| siemens | simatic_drive_controller_family | — | — |
| siemens | simatic_et_200_sp_open_controller_cpu_1515sp_pc2_firmware | < 21.9 | 21.9 |
| siemens | simatic_et_200sp_open_controller_cpu_1515sp_pc | — | — |
| siemens | simatic_et_200sp_open_controller_cpu_1515sp_pc2 | — | — |
| siemens | simatic_s7-1200_cpu_12_1211c_firmware | < 4.5.0 | 4.5.0 |
| siemens | simatic_s7-1200_cpu_12_1212c_firmware | < 4.5.0 | 4.5.0 |
| siemens | simatic_s7-1200_cpu_12_1212fc_firmware | < 4.5.0 | 4.5.0 |
| siemens | simatic_s7-1200_cpu_12_1214c_firmware | < 4.5.0 | 4.5.0 |
| siemens | simatic_s7-1200_cpu_12_1214fc_firmware | < 4.5.0 | 4.5.0 |
| siemens | simatic_s7-1200_cpu_12_1215c_firmware | < 4.5.0 | 4.5.0 |
| siemens | simatic_s7-1200_cpu_12_1215fc_firmware | < 4.5.0 | 4.5.0 |
| siemens | simatic_s7-1200_cpu_12_1217c_firmware | < 4.5.0 | 4.5.0 |
| siemens | simatic_s7-1200_cpu_family | — | — |
| siemens | simatic_s7-1500_cpu_1510sp-1_firmware | < 2.9.2 | 2.9.2 |
| siemens | simatic_s7-1500_cpu_1510sp_firmware | < 2.9.2 | 2.9.2 |
| siemens | simatic_s7-1500_cpu_1511-1_firmware | < 2.9.2 | 2.9.2 |
| siemens | simatic_s7-1500_cpu_1511t-1_firmware | < 2.9.2 | 2.9.2 |
| siemens | simatic_s7-1500_cpu_1511tf-1_firmware | < 2.9.2 | 2.9.2 |
| siemens | simatic_s7-1500_cpu_1512c-1_firmware | < 2.9.2 | 2.9.2 |
| siemens | simatic_s7-1500_cpu_1512sp-1_firmware | < 2.9.2 | 2.9.2 |
| siemens | simatic_s7-1500_cpu_1512spf-1_firmware | < 2.9.2 | 2.9.2 |
| siemens | simatic_s7-1500_cpu_1513-1_firmware | < 2.9.2 | 2.9.2 |
| siemens | simatic_s7-1500_cpu_1513f-1_firmware | < 2.9.2 | 2.9.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SINUMERIK ONE and SINUMERIK MC
cisa_ics·2022-11-10·CVSS 9.3
[CRITICAL] Siemens SINUMERIK ONE and SINUMERIK MC
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINUMERIK ONE and SINUMERIK MC
Last RevisedNovember 10, 2022
Alert CodeICSA-22-314-04
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.3
- ATTENTION: Low attack complexity
- Vendor: Siemens
- Equipment: SINUMERIK ONE and SINUMERIK MC
- Vulnerability: Insufficiently Prot
CISA ICS
Siemens SIMATIC S7-1200 and S7-1500 CPU Families
cisa_ics·2022-10-13·CVSS 9.3
[CRITICAL] Siemens SIMATIC S7-1200 and S7-1500 CPU Families
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SIMATIC S7-1200 and S7-1500 CPU Families
Last RevisedOctober 13, 2022
Alert CodeICSA-22-286-04
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.3
- ATTENTION: Low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1200 and S7-1500 CPU families
- Vulnerability: Insufficiently Protected Credentials
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could expose confidential configuration data.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Siemens reports this vulnerability affects the SIMATIC S7-1200 and S7-1500 CPU product families:
- SIMATIC Dri
GHSA
GHSA-45px-m6q7-hv4p: A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2
ghsa_unreviewed·2022-10-11
CVE-2022-38465 [HIGH] CWE-522 GHSA-45px-m6q7-hv4p: A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2
A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V21.9), SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (All versions < V4.5.0), SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions < V2.9.2), SIMATIC S7-1500 Software Controller (All versions < V21.9), SIMATIC S7-PLCSIM Advanced (All versions < V4.0). Affected products protect the built-in global private key in a way that cannot be considered sufficient any longer. The key is used for the legacy protection of confidential configuration data and the legacy PG/PC and HMI communication.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-10-11
Published