PT-2022-25295 · Siemens · Simatic Hmi Ktp1200 Basic+9
Published
2022-10-11
·
Updated
2022-10-14
·
CVE-2022-40227
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
SIMATIC HMI Comfort Panels (incl. SIPLUS variants) versions prior to V17 Update 4
SIMATIC HMI KTP Mobile Panels versions prior to V17 Update 4
SIMATIC HMI KTP1200 Basic versions prior to V17 Update 5
SIMATIC HMI KTP400 Basic versions prior to V17 Update 5
SIMATIC HMI KTP700 Basic versions prior to V17 Update 5
SIMATIC HMI KTP900 Basic versions prior to V17 Update 5
SIPLUS HMI KTP1200 BASIC versions prior to V17 Update 5
SIPLUS HMI KTP400 BASIC versions prior to V17 Update 5
SIPLUS HMI KTP700 BASIC versions prior to V17 Update 5
SIPLUS HMI KTP900 BASIC versions prior to V17 Update 5
Description
The affected devices do not properly validate input sent to certain services over TCP, which could allow an unauthenticated remote attacker to cause a permanent denial of service condition by sending specially crafted TCP packets. This condition would require a device reboot.
Recommendations
For SIMATIC HMI Comfort Panels (incl. SIPLUS variants) versions prior to V17 Update 4, update to V17 Update 4 or later.
For SIMATIC HMI KTP Mobile Panels versions prior to V17 Update 4, update to V17 Update 4 or later.
For SIMATIC HMI KTP1200 Basic versions prior to V17 Update 5, update to V17 Update 5 or later.
For SIMATIC HMI KTP400 Basic versions prior to V17 Update 5, update to V17 Update 5 or later.
For SIMATIC HMI KTP700 Basic versions prior to V17 Update 5, update to V17 Update 5 or later.
For SIMATIC HMI KTP900 Basic versions prior to V17 Update 5, update to V17 Update 5 or later.
For SIPLUS HMI KTP1200 BASIC versions prior to V17 Update 5, update to V17 Update 5 or later.
For SIPLUS HMI KTP400 BASIC versions prior to V17 Update 5, update to V17 Update 5 or later.
For SIPLUS HMI KTP700 BASIC versions prior to V17 Update 5, update to V17 Update 5 or later.
For SIPLUS HMI KTP900 BASIC versions prior to V17 Update 5, update to V17 Update 5 or later.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simatic Hmi Comfort Panels
Simatic Hmi Ktp Mobile Panels
Simatic Hmi Ktp1200 Basic
Simatic Hmi Ktp400 Basic
Simatic Hmi Ktp700 Basic
Simatic Hmi Ktp900 Basic
Siplus Hmi Ktp1200 Basic
Siplus Hmi Ktp400 Basic
Siplus Hmi Ktp700 Basic
Siplus Hmi Ktp900 Basic