CVE-2022-34819
Description
A vulnerability has been identified in SIMATIC CP 1242-7 V2 (All versions < V3.3.46), SIMATIC CP 1243-1 (All versions < V3.3.46), SIMATIC CP 1243-7 LTE EU (All versions < V3.3.46), SIMATIC CP 1243-7 LTE US (All versions < V3.3.46), SIMATIC CP 1243-8 IRC (All versions < V3.3.46), SIMATIC CP 1542SP-1 IRC (All versions >= V2.0 < V2.2.28), SIMATIC CP 1543-1 (All versions < V3.0.22), SIMATIC CP 1543SP-1 (All versions >= V2.0 < V2.2.28), SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL (All versions >= V2.0 < V2.2.28), SIPLUS ET 200SP CP 1543SP-1 ISEC (All versions >= V2.0 < V2.2.28), SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL (All versions >= V2.0 < V2.2.28), SIPLUS NET CP 1242-7 V2 (All versions < V3.3.46), SIPLUS NET CP 1543-1 (All versions < V3.0.22), SIPLUS S7-1200 CP 1243-1 (All versions < V3.3.46), SIPLUS S7-1200 CP 1243-1 RAIL (All versions < V3.3.46). The application lacks proper validation of user-supplied data when parsing specific messages. This could result in a heap-based buffer overflow. An attacker could leverage this vulnerability to execute code in the context of device.
Affected products
15- Siemens/SIMATIC CP 1242-7 V2v5Range: All versions < V3.3.46
- Range: All versions < V3.3.46
All versions < V3.3.46+ 1 more
- (no CPE)range: All versions < V3.3.46
- (no CPE)range: All versions < V3.3.46
- Range: All versions < V3.3.46
- Range: All versions >= V2.0 < V2.2.28
- Range: All versions < V3.0.22
- Range: All versions >= V2.0 < V2.2.28
All versions >= V2.0 < V2.2.28+ 1 more
- (no CPE)range: All versions >= V2.0 < V2.2.28
- (no CPE)range: All versions >= V2.0 < V2.2.28
- Siemens/SIPLUS ET 200SP CP 1543SP-1 ISECv5Range: All versions >= V2.0 < V2.2.28
- Siemens/SIPLUS NET CP 1242-7 V2v5Range: All versions < V3.3.46
- Range: All versions < V3.0.22
All versions < V3.3.46+ 1 more
- (no CPE)range: All versions < V3.3.46
- (no CPE)range: All versions < V3.3.46
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.