Denial of Service Vulnerability in Siemens SIMATIC Products
CVE-2022-47374

7.5HIGH

Summary

A vulnerability has been discovered in Siemens SIMATIC products and SINAMICS S120 series that improperly handles HTTP(S) requests to the web server. This flaw can lead to resource exhaustion, making the device unable to process requests, thus potentially causing a denial of service condition. Affected systems include various versions of SIMATIC S7-400 CPUs and the SIMATIC PC-Station Plus, requiring users to implement necessary precautions.

Affected Version(s)

SIMATIC PC-Station Plus All versions

SIMATIC S7-400 CPU 412-2 PN V7 All versions

SIMATIC S7-400 CPU 414-3 PN/DP V7 All versions

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.