PT-2022-7652 · Siemens · Siplus Logo! 24Ce+6
Published
2022-10-11
·
Updated
2024-09-10
·
CVE-2022-36361
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LOGO! 12/24RCE versions 6ED1052-1MD08-0BA1
LOGO! 12/24RCEo versions 6ED1052-2MD08-0BA1
LOGO! 230RCE versions 6ED1052-1FB08-0BA1
LOGO! 230RCEo versions 6ED1052-2FB08-0BA1
LOGO! 24CE versions 6ED1052-1CC08-0BA1
LOGO! 24CEo versions 6ED1052-2CC08-0BA1
LOGO! 24RCE versions 6ED1052-1HB08-0BA1
LOGO! 24RCEo versions 6ED1052-2HB08-0BA1
SIPLUS LOGO! 12/24RCE versions 6AG1052-1MD08-7BA1
SIPLUS LOGO! 12/24RCEo versions 6AG1052-2MD08-7BA1
SIPLUS LOGO! 230RCE versions 6AG1052-1FB08-7BA1
SIPLUS LOGO! 230RCEo versions 6AG1052-2FB08-7BA1
SIPLUS LOGO! 24CE versions 6AG1052-1CC08-7BA1
SIPLUS LOGO! 24CEo versions 6AG1052-2CC08-7BA1
SIPLUS LOGO! 24RCE versions 6AG1052-1HB08-7BA1
SIPLUS LOGO! 24RCEo versions 6AG1052-2HB08-7BA1
Description
The affected devices do not properly validate the structure of TCP packets in several methods, which could allow an attacker to cause buffer overflows, gain control over the instruction counter, and run custom code. This issue is related to the programmatic logic controllers Siemens LOGO! and SIPLUS LOGO!.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Logo! 12/24Rce
Logo! 230Rce
Logo! 24Ce
Logo! 24Ceo
Siplus Logo! 12/24Rce
Siplus Logo! 230Rce
Siplus Logo! 24Ce