VYPR
Medium severity5.3NVD Advisory· Published Oct 11, 2022· Updated Jun 17, 2026

CVE-2022-36363

CVE-2022-36363

Description

A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA1) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA1) (All versions), LOGO! 230RCE (6ED1052-1FB08-0BA1) (All versions), LOGO! 230RCEo (6ED1052-2FB08-0BA1) (All versions), LOGO! 24CE (6ED1052-1CC08-0BA1) (All versions), LOGO! 24CEo (6ED1052-2CC08-0BA1) (All versions), LOGO! 24RCE (6ED1052-1HB08-0BA1) (All versions), LOGO! 24RCEo (6ED1052-2HB08-0BA1) (All versions), SIPLUS LOGO! 12/24RCE (6AG1052-1MD08-7BA1) (All versions), SIPLUS LOGO! 12/24RCEo (6AG1052-2MD08-7BA1) (All versions), SIPLUS LOGO! 230RCE (6AG1052-1FB08-7BA1) (All versions), SIPLUS LOGO! 230RCEo (6AG1052-2FB08-7BA1) (All versions), SIPLUS LOGO! 24CE (6AG1052-1CC08-7BA1) (All versions), SIPLUS LOGO! 24CEo (6AG1052-2CC08-7BA1) (All versions), SIPLUS LOGO! 24RCE (6AG1052-1HB08-7BA1) (All versions), SIPLUS LOGO! 24RCEo (6AG1052-2HB08-7BA1) (All versions). Affected devices do not properly validate an offset value which can be defined in TCP packets when calling a method. This could allow an attacker to retrieve parts of the content of the memory.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

17
  • All versions+ 11 more
    • (no CPE)range: All versions
    • (no CPE)range: 0
    • (no CPE)range: 0
    • (no CPE)range: 0
    • (no CPE)range: 0
    • (no CPE)range: 0
    • (no CPE)range: 0
    • (no CPE)range: 0
    • (no CPE)range: 0
    • (no CPE)range: 0
    • (no CPE)range: 0
    • (no CPE)range: 0
  • Siemens/LOGO! 230RCEv5
    Range: 0
  • Siemens/LOGO! 230RCEov5
    Range: 0
  • Siemens/LOGO! 24CEv5
    Range: 0
  • Siemens/LOGO! 24CEov5
    Range: 0
  • Siemens/SIPLUS LOGO! 230RCEov5
    Range: 0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.