PT-2023-14146 · Siemens · Logo! 24Ce+6
Sebastien Leger
·
Published
2023-12-12
·
Updated
2024-09-10
·
CVE-2022-42784
CVSS v3.1
7.6
High
| Vector | AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LOGO! 12/24RCE versions 8.3 and later
LOGO! 12/24RCEo versions 8.3 and later
LOGO! 230RCE versions 8.3 and later
LOGO! 230RCEo versions 8.3 and later
LOGO! 24CE versions 8.3 and later
LOGO! 24CEo versions 8.3 and later
LOGO! 24RCE versions 8.3 and later
LOGO! 24RCEo versions 8.3 and later
SIPLUS LOGO! 12/24RCE versions 8.3 and later
SIPLUS LOGO! 12/24RCEo versions 8.3 and later
SIPLUS LOGO! 230RCE versions 8.3 and later
SIPLUS LOGO! 230RCEo versions 8.3 and later
SIPLUS LOGO! 24CE versions 8.3 and later
SIPLUS LOGO! 24CEo versions 8.3 and later
SIPLUS LOGO! 24RCE versions 8.3 and later
SIPLUS LOGO! 24RCEo versions 8.3 and later
Description
The affected devices are vulnerable to an electromagnetic fault injection, which could allow an attacker to dump and debug the firmware, including the manipulation of memory. This could further allow the injection of public keys of custom-created key pairs, which are then signed by the product CA. The generation of a custom certificate enables communication with, and impersonation of, any device of the same version.
Recommendations
For LOGO! 12/24RCE versions 8.3 and later, update to a version that includes a fix for this issue.
For LOGO! 12/24RCEo versions 8.3 and later, update to a version that includes a fix for this issue.
For LOGO! 230RCE versions 8.3 and later, update to a version that includes a fix for this issue.
For LOGO! 230RCEo versions 8.3 and later, update to a version that includes a fix for this issue.
For LOGO! 24CE versions 8.3 and later, update to a version that includes a fix for this issue.
For LOGO! 24CEo versions 8.3 and later, update to a version that includes a fix for this issue.
For LOGO! 24RCE versions 8.3 and later, update to a version that includes a fix for this issue.
For LOGO! 24RCEo versions 8.3 and later, update to a version that includes a fix for this issue.
For SIPLUS LOGO! 12/24RCE versions 8.3 and later, update to a version that includes a fix for this issue.
For SIPLUS LOGO! 12/24RCEo versions 8.3 and later, update to a version that includes a fix for this issue.
For SIPLUS LOGO! 230RCE versions 8.3 and later, update to a version that includes a fix for this issue.
For SIPLUS LOGO! 230RCEo versions 8.3 and later, update to a version that includes a fix for this issue.
For SIPLUS LOGO! 24CE versions 8.3 and later, update to a version that includes a fix for this issue.
For SIPLUS LOGO! 24CEo versions 8.3 and later, update to a version that includes a fix for this issue.
For SIPLUS LOGO! 24RCE versions 8.3 and later, update to a version that includes a fix for this issue.
For SIPLUS LOGO! 24RCEo versions 8.3 and later, update to a version that includes a fix for this issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Logo! 12/24Rce
Logo! 230Rce
Logo! 24Ce
Logo! 24Ceo
Siplus Logo! 12/24Rce
Siplus Logo! 230Rce
Siplus Logo! 24Ce