PT-2022-3381 · Siemens · Desigo Pxc3+3

Published

2022-05-10

·

Updated

2022-05-19

·

CVE-2021-41545

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Desigo DXR2 versions prior to V01.21.142.5-22 Desigo PXC3 versions prior to V01.21.142.4-18 Desigo PXC4 versions prior to V02.20.142.10-10884 Desigo PXC5 versions prior to V02.20.142.10-10884
Description The issue is related to an error in handling exceptions in the BACnet protocol implementation of the Desigo DXR2, PXC3, PXC4, and PXC5 station automation modules. Exploitation of this issue may allow an attacker to cause a denial of service. When the controller receives a specific BACnet protocol packet, an exception causes the BACnet communication function to go into an "out of work" state and could result in the controller going into a "factory reset" state.
Recommendations For Desigo DXR2 versions prior to V01.21.142.5-22, update to version V01.21.142.5-22 or later. For Desigo PXC3 versions prior to V01.21.142.4-18, update to version V01.21.142.4-18 or later. For Desigo PXC4 versions prior to V02.20.142.10-10884, update to version V02.20.142.10-10884 or later. For Desigo PXC5 versions prior to V02.20.142.10-10884, update to version V02.20.142.10-10884 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04152
CVE-2021-41545

Affected Products

Desigo Dxr2
Desigo Pxc3
Desigo Pxc4
Desigo Pxc5