Denial of Service Vulnerability in Siemens SIMATIC CP 442-1 and CP 443-1 Devices
CVE-2022-27640
6.5MEDIUM
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 20 May 2022
Summary
A vulnerability exists in the Siemens SIMATIC CP 442-1 RNA and CP 443-1 RNA devices that affects all versions prior to V1.5.18. The issue arises from improper handling of excessive Address Resolution Protocol (ARP) broadcast requests. An attacker could exploit this vulnerability to launch ARP storming attacks, potentially resulting in a denial of service by causing the affected devices to become unresponsive and reboot intermittently.
Affected Version(s)
SIMATIC CP 442-1 RNA All versions < V1.5.18
SIMATIC CP 443-1 RNA All versions < V1.5.18
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved