Memory Retrieval Vulnerability in LOGO! 12/24RCE and SIPLUS LOGO! Products by Siemens
CVE-2022-36363
5.3MEDIUM
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 11 October 2022
Summary
A vulnerability in Siemens LOGO! 12/24RCE and SIPLUS LOGO! devices exists due to improper validation of offset values defined in TCP packets during method calls. This flaw can potentially enable attackers to access sensitive memory content, posing a significant risk to the integrity and confidentiality of system data. Users of these products should implement recommended security measures and monitor for any suspicious activity.
Affected Version(s)
LOGO! 12/24RCE 0
LOGO! 12/24RCEo 0
LOGO! 230RCE 0
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved