Input Validation Flaw in SIMATIC eaSie Core Package by Siemens
CVE-2021-44221

7.5HIGH

Key Information:

Vendor
Siemens
Vendor
CVE Published:
12 July 2022

Summary

A vulnerability exists in the SIMATIC eaSie Core Package affecting all versions prior to V22.00, where improper input validation in the message passing framework can be exploited by remote attackers. This flaw could result in a denial of service, disrupting the normal operation of the system. It is crucial for users of the affected product to implement available security updates and thoroughly assess their systems for potential exploits.

Affected Version(s)

SIMATIC eaSie Core Package All versions < V22.00

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.