Denial of Service Vulnerability in Siemens SIMATIC Products
CVE-2022-47374
7.5HIGH
Key Information:
- Vendor
- Siemens
- Status
- Vendor
- CVE Published:
- 12 December 2023
Summary
A vulnerability has been discovered in Siemens SIMATIC products and SINAMICS S120 series that improperly handles HTTP(S) requests to the web server. This flaw can lead to resource exhaustion, making the device unable to process requests, thus potentially causing a denial of service condition. Affected systems include various versions of SIMATIC S7-400 CPUs and the SIMATIC PC-Station Plus, requiring users to implement necessary precautions.
Affected Version(s)
SIMATIC PC-Station Plus All versions
SIMATIC S7-400 CPU 412-2 PN V7 All versions
SIMATIC S7-400 CPU 414-3 PN/DP V7 All versions
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved