Input validation error in Siemens products - CVE-2022-40227

 

Input validation error in Siemens products - CVE-2022-40227

Published: October 11, 2022


Vulnerability identifier: #VU68121
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-40227
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send a specially crafted TCP packet to the application and perform a denial of service (DoS) attack.


Affected software

SIMATIC HMI Comfort Panels
SIMATIC HMI KTP Mobile Panels
SIMATIC HMI KTP400 Basic
SIMATIC HMI KTP700 Basic
SIMATIC HMI KTP900
SIMATIC HMI KTP1200
SIPLUS HMI KTP400 BASIC
SIPLUS HMI KTP700 BASIC
SIPLUS HMI KTP900 BASIC
SIPLUS HMI KTP1200 BASIC

How to mitigate CVE-2022-40227

Install updates from vendor's website.

SIMATIC HMI Comfort Panels - update to 17 Update 4
SIMATIC HMI KTP Mobile Panels - update to 17 Update 4
SIMATIC HMI KTP400 Basic - update to 17 Update 5
SIMATIC HMI KTP700 Basic - update to 17 Update 5
SIMATIC HMI KTP900 - update to 17 Update 5
SIMATIC HMI KTP1200 - update to 17 Update 5
SIPLUS HMI KTP400 BASIC - update to 17 Update 5
SIPLUS HMI KTP700 BASIC - update to 17 Update 5
SIPLUS HMI KTP900 BASIC - update to 17 Update 5
SIPLUS HMI KTP1200 BASIC - update to 17 Update 5

External References

Related Security Bulletins