Remote Code Execution Vulnerability in LOGO! Devices from Siemens
CVE-2022-36362

7.5HIGH

Key Information:

Vendor
Siemens
Vendor
CVE Published:
11 October 2022

Summary

A vulnerability in various LOGO! devices from Siemens enables an unauthenticated remote attacker to manipulate the devices' IP addresses. This flaw occurs due to insufficient validation when interacting with the devices. Consequently, the affected devices become unreachable, requiring a power cycle for recovery. All versions of specific models of LOGO! are impacted, highlighting the need for immediate attention to secure these devices against potential exploitation.

Affected Version(s)

LOGO! 12/24RCE All versions

LOGO! 12/24RCE All versions

LOGO! 12/24RCEo All versions

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.