Memory Retrieval Vulnerability in LOGO! 12/24RCE and SIPLUS LOGO! Products by Siemens
CVE-2022-36363

5.3MEDIUM

Key Information:

Vendor
Siemens
Vendor
CVE Published:
11 October 2022

Summary

A vulnerability in Siemens LOGO! 12/24RCE and SIPLUS LOGO! devices exists due to improper validation of offset values defined in TCP packets during method calls. This flaw can potentially enable attackers to access sensitive memory content, posing a significant risk to the integrity and confidentiality of system data. Users of these products should implement recommended security measures and monitor for any suspicious activity.

Affected Version(s)

LOGO! 12/24RCE 0

LOGO! 12/24RCEo 0

LOGO! 230RCE 0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.