Resource exhaustion in Siemens products - CVE-2022-38371

 

Resource exhaustion in Siemens products - CVE-2022-38371

Published: October 13, 2022


Vulnerability identifier: #VU68283
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-38371
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources in the FTP server. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

Nucleus NET
Nucleus Source Code
Nucleus ReadyStart
WAGO PLC Series 750-829
WAGO PLC Series 750-330
WAGO PLC Series 750-332
WAGO PLC Series 750-352
WAGO PLC Series 750-362
WAGO PLC Series 750-363
WAGO PLC Series 750-364
WAGO PLC Series 750-365
WAGO PLC Series 750-823
WAGO PLC Series 750-831
WAGO PLC Series 750-832
WAGO PLC Series 750-852
WAGO PLC Series 750-862
WAGO PLC Series 750-880
WAGO PLC Series 750-881
WAGO PLC Series 750-882
WAGO PLC Series 750-885
WAGO PLC Series 750-889
WAGO PLC Series 750-890
WAGO PLC Series 750-891
WAGO PLC Series 750-893
TALON TC Modular (BACnet)
TALON TC Compact (BACnet)
APOGEE PXC Modular (P2 Ethernet)
APOGEE PXC Modular (BACnet)
APOGEE PXC Compact (P2 Ethernet)
APOGEE PXC Compact (BACnet)
APOGEE MEC (PPC) (P2 Ethernet)
APOGEE MEC (PPC) (BACnet)
APOGEE MBC (PPC) (P2 Ethernet)
APOGEE MBC (PPC) (BACnet)
Desigo PXC128-U
Desigo PXC200-E.D
Desigo PXM20-E
Desigo PXC100-E.D
Desigo PXC12-E.D
Desigo PXC00-E.D
Desigo PXC00-U
Desigo PXC001-E.D
Desigo PXC64-U
Desigo PXC22-E.D
Desigo PXC22.1-E.D
Desigo PXC50-E.D
Desigo PXC36.1-E.D

How to mitigate CVE-2022-38371

Install updates from vendor's website.

Nucleus ReadyStart - update to 2017.02.4_patch_CVE-2022-38371

External References

Related Security Bulletins