Denial of Service Vulnerability in Siemens SIMATIC CP 442-1 and CP 443-1 Devices
CVE-2022-27640

6.5MEDIUM

Key Information:

Vendor
Siemens
Vendor
CVE Published:
20 May 2022

Summary

A vulnerability exists in the Siemens SIMATIC CP 442-1 RNA and CP 443-1 RNA devices that affects all versions prior to V1.5.18. The issue arises from improper handling of excessive Address Resolution Protocol (ARP) broadcast requests. An attacker could exploit this vulnerability to launch ARP storming attacks, potentially resulting in a denial of service by causing the affected devices to become unresponsive and reboot intermittently.

Affected Version(s)

SIMATIC CP 442-1 RNA All versions < V1.5.18

SIMATIC CP 443-1 RNA All versions < V1.5.18

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.