Remote Code Execution Vulnerability in LOGO! Devices from Siemens
CVE-2022-36362
7.5HIGH
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 11 October 2022
Summary
A vulnerability in various LOGO! devices from Siemens enables an unauthenticated remote attacker to manipulate the devices' IP addresses. This flaw occurs due to insufficient validation when interacting with the devices. Consequently, the affected devices become unreachable, requiring a power cycle for recovery. All versions of specific models of LOGO! are impacted, highlighting the need for immediate attention to secure these devices against potential exploitation.
Affected Version(s)
LOGO! 12/24RCE All versions
LOGO! 12/24RCE All versions
LOGO! 12/24RCEo All versions
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved