PT-2022-27017 · Siemens · Sicam Pas/Pqs

Published

2022-12-13

·

Updated

2023-10-17

·

CVE-2022-43723

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions SICAM PAS/PQS versions prior to 7.0 SICAM PAS/PQS versions 7.0 through 8.05
Description A vulnerability has been identified in the affected software, where it does not properly validate the input for a certain parameter in the s7ontcp.dll. This could allow an unauthenticated remote attacker to send messages and create a denial of service condition as the application crashes.
Recommendations For SICAM PAS/PQS versions prior to 7.0, update to version 7.0 or later. For SICAM PAS/PQS versions 7.0 through 8.05, update to version 8.06 or later. As a temporary workaround, consider restricting access to the s7ontcp.dll to minimize the risk of exploitation.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2022-43723

Affected Products

Sicam Pas/Pqs