Resource exhaustion in Siemens products - CVE-2022-46351
Published: December 16, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker on the local network can send specially crafted PROFINET DCP packets, trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
SCALANCE X204RNA (PRP)
SCALANCE X204RNA EEC (HSR)
SCALANCE X204RNA EEC (PRP)
SCALANCE X204RNA EEC (PRP/HSR)
How to mitigate CVE-2022-46351
SCALANCE X204RNA (PRP) - update to 3.2.7
SCALANCE X204RNA EEC (HSR) - update to 3.2.7
SCALANCE X204RNA EEC (PRP) - update to 3.2.7
SCALANCE X204RNA EEC (PRP/HSR) - update to 3.2.7