PT-2023-9402 · Siemens · Siplus S7-1200 Cp 1243-1 Rail+20

Published

2023-04-11

·

Updated

2024-09-10

·

CVE-2022-43716

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions SIMATIC CP 1242-7 V2 versions prior to V3.4.29 SIMATIC CP 1243-1 versions prior to V3.4.29 SIMATIC CP 1243-1 DNP3 versions prior to V3.4.29 SIMATIC CP 1243-1 IEC versions prior to V3.4.29 SIMATIC CP 1243-7 LTE EU versions prior to V3.4.29 SIMATIC CP 1243-7 LTE US versions prior to V3.4.29 SIMATIC CP 1243-8 IRC versions prior to V3.4.29 SIMATIC CP 1542SP-1 versions prior to V2.3 SIMATIC CP 1542SP-1 IRC versions prior to V2.3 SIMATIC CP 1543SP-1 versions prior to V2.3 SIMATIC CP 443-1 versions prior to V3.3 SIMATIC CP 443-1 Advanced versions prior to V3.3 SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL versions prior to V2.3 SIPLUS ET 200SP CP 1543SP-1 ISEC versions prior to V2.3 SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL versions prior to V2.3 SIPLUS NET CP 1242-7 V2 versions prior to V3.4.29 SIPLUS NET CP 443-1 versions prior to V3.3 SIPLUS NET CP 443-1 Advanced versions prior to V3.3 SIPLUS S7-1200 CP 1243-1 versions prior to V3.4.29 SIPLUS S7-1200 CP 1243-1 RAIL versions prior to V3.4.29 SIPLUS TIM 1531 IRC versions prior to V2.3.6 TIM 1531 IRC versions prior to V2.3.6
Description The webserver of the affected products contains a vulnerability that may lead to a denial of service condition. An attacker may cause a denial of service situation which leads to a restart of the webserver of the affected product. The vulnerability is related to the use of memory after it has been freed.
Recommendations For SIMATIC CP 1242-7 V2 versions prior to V3.4.29, update to version V3.4.29 or later. For SIMATIC CP 1243-1 versions prior to V3.4.29, update to version V3.4.29 or later. For SIMATIC CP 1243-1 DNP3 versions prior to V3.4.29, update to version V3.4.29 or later. For SIMATIC CP 1243-1 IEC versions prior to V3.4.29, update to version V3.4.29 or later. For SIMATIC CP 1243-7 LTE EU versions prior to V3.4.29, update to version V3.4.29 or later. For SIMATIC CP 1243-7 LTE US versions prior to V3.4.29, update to version V3.4.29 or later. For SIMATIC CP 1243-8 IRC versions prior to V3.4.29, update to version V3.4.29 or later. For SIMATIC CP 1542SP-1 versions prior to V2.3, update to version V2.3 or later. For SIMATIC CP 1542SP-1 IRC versions prior to V2.3, update to version V2.3 or later. For SIMATIC CP 1543SP-1 versions prior to V2.3, update to version V2.3 or later. For SIMATIC CP 443-1 versions prior to V3.3, update to version V3.3 or later. For SIMATIC CP 443-1 Advanced versions prior to V3.3, update to version V3.3 or later. For SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL versions prior to V2.3, update to version V2.3 or later. For SIPLUS ET 200SP CP 1543SP-1 ISEC versions prior to V2.3, update to version V2.3 or later. For SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL versions prior to V2.3, update to version V2.3 or later. For SIPLUS NET CP 1242-7 V2 versions prior to V3.4.29, update to version V3.4.29 or later. For SIPLUS NET CP 443-1 versions prior to V3.3, update to version V3.3 or later. For SIPLUS NET CP 443-1 Advanced versions prior to V3.3, update to version V3.3 or later. For SIPLUS S7-1200 CP 1243-1 versions prior to V3.4.29, update to version V3.4.29 or later. For SIPLUS S7-1200 CP 1243-1 RAIL versions prior to V3.4.29, update to version V3.4.29 or later. For SIPLUS TIM 1531 IRC versions prior to V2.3.6, update to version V2.3.6 or later. For TIM 1531 IRC versions prior to V2.3.6, update to version V2.3.6 or later.

Fix

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2024-07174
CVE-2022-43716

Affected Products

Simatic Cp 1242-7 V2
Simatic Cp 1243-1
Simatic Cp 1243-1 Dnp3
Simatic Cp 1243-1 Iec
Simatic Cp 1243-7 Lte Eu
Simatic Cp 1243-7 Lte Us
Simatic Cp 1243-8 Irc
Simatic Cp 1542Sp-1 Irc
Simatic Cp 1543Sp-1
Simatic Cp 443-1
Simatic Cp 443-1 Advanced
Siplus Et 200Sp Cp 1542Sp-1 Irc Tx Rail
Siplus Et 200Sp Cp 1543Sp-1 Isec
Siplus Et 200Sp Cp 1543Sp-1 Isec Tx Rail
Siplus Net Cp 1242-7 V2
Siplus Net Cp 443-1
Siplus Net Cp 443-1 Advanced
Siplus S7-1200 Cp 1243-1
Siplus S7-1200 Cp 1243-1 Rail
Siplus Tim 1531 Irc
Tim 1531 Irc