PT-2024-2314 · Siemens · Sinteso Fs20 En Fire Panel Fc20 Mp6+21
Published
2024-03-12
·
Updated
2024-05-14
·
CVE-2024-22041
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cerberus PRO EN Engineering Tool versions prior to MP4
Cerberus PRO EN Fire Panel FC72x IP6 versions prior to IP8 SR4
Cerberus PRO EN Fire Panel FC72x IP7 versions prior to IP8 SR4
Cerberus PRO EN Fire Panel FC72x IP8 versions prior to IP8 SR4
Cerberus PRO EN X200 Cloud Distribution IP7 versions prior to V4.3.5618
Cerberus PRO EN X200 Cloud Distribution IP8 versions prior to V4.3.5618
Cerberus PRO EN X300 Cloud Distribution IP7 versions prior to V4.3.5617
Cerberus PRO EN X300 Cloud Distribution IP8 versions prior to V4.3.5617
Cerberus PRO UL Compact Panel FC922/924 versions prior to MP4
Cerberus PRO UL Engineering Tool versions prior to MP4
Cerberus PRO UL X300 Cloud Distribution versions prior to V4.3.0001
Desigo Fire Safety UL Compact Panel FC2025/2050 versions prior to MP4
Desigo Fire Safety UL Engineering Tool versions prior to MP4
Desigo Fire Safety UL X300 Cloud Distribution versions prior to V4.3.0001
Sinteso FS20 EN Engineering Tool versions prior to MP4
Sinteso FS20 EN Fire Panel FC20 MP6 versions prior to MP8 SR4
Sinteso FS20 EN Fire Panel FC20 MP7 versions prior to MP8 SR4
Sinteso FS20 EN Fire Panel FC20 MP8 versions prior to MP8 SR4
Sinteso FS20 EN X200 Cloud Distribution MP7 versions prior to V4.3.5618
Sinteso FS20 EN X200 Cloud Distribution MP8 versions prior to V4.3.5618
Sinteso FS20 EN X300 Cloud Distribution MP7 versions prior to V4.3.5617
Sinteso FS20 EN X300 Cloud Distribution MP8 versions prior to V4.3.5617
Sinteso Mobile versions prior to V4.3.0001
Description
The vulnerability is related to the network communication library in the affected systems, which improperly handles memory buffers when parsing X.509 certificates. This could allow an unauthenticated remote attacker to crash the network service, resulting in a denial of service. The issue is caused by a buffer overflow when analyzing X.509 certificates.
Recommendations
For Cerberus PRO EN Engineering Tool versions prior to MP4, update to a version that includes the fix for this issue.
For Cerberus PRO EN Fire Panel FC72x IP6 versions prior to IP8 SR4, update to a version that includes the fix for this issue.
For Cerberus PRO EN Fire Panel FC72x IP7 versions prior to IP8 SR4, update to a version that includes the fix for this issue.
For Cerberus PRO EN Fire Panel FC72x IP8 versions prior to IP8 SR4, update to a version that includes the fix for this issue.
For Cerberus PRO EN X200 Cloud Distribution IP7 versions prior to V4.3.5618, update to a version that includes the fix for this issue.
For Cerberus PRO EN X200 Cloud Distribution IP8 versions prior to V4.3.5618, update to a version that includes the fix for this issue.
For Cerberus PRO EN X300 Cloud Distribution IP7 versions prior to V4.3.5617, update to a version that includes the fix for this issue.
For Cerberus PRO EN X300 Cloud Distribution IP8 versions prior to V4.3.5617, update to a version that includes the fix for this issue.
For Cerberus PRO UL Compact Panel FC922/924 versions prior to MP4, update to a version that includes the fix for this issue.
For Cerberus PRO UL Engineering Tool versions prior to MP4, update to a version that includes the fix for this issue.
For Cerberus PRO UL X300 Cloud Distribution versions prior to V4.3.0001, update to a version that includes the fix for this issue.
For Desigo Fire Safety UL Compact Panel FC2025/2050 versions prior to MP4, update to a version that includes the fix for this issue.
For Desigo Fire Safety UL Engineering Tool versions prior to MP4, update to a version that includes the fix for this issue.
For Desigo Fire Safety UL X300 Cloud Distribution versions prior to V4.3.0001, update to a version that includes the fix for this issue.
For Sinteso FS20 EN Engineering Tool versions prior to MP4, update to a version that includes the fix for this issue.
For Sinteso FS20 EN Fire Panel FC20 MP6 versions prior to MP8 SR4, update to a version that includes the fix for this issue.
For Sinteso FS20 EN Fire Panel FC20 MP7 versions prior to MP8 SR4, update to a version that includes the fix for this issue.
For Sinteso FS20 EN Fire Panel FC20 MP8 versions prior to MP8 SR4, update to a version that includes the fix for this issue.
For Sinteso FS20 EN X200 Cloud Distribution MP7 versions prior to V4.3.5618, update to a version that includes the fix for this issue.
For Sinteso FS20 EN X200 Cloud Distribution MP8 versions prior to V4.3.5618, update to a version that includes the fix for this issue.
For Sinteso FS20 EN X300 Cloud Distribution MP7 versions prior to V4.3.5617, update to a version that includes the fix for this issue.
For Sinteso FS20 EN X300 Cloud Distribution MP8 versions prior to V4.3.5617, update to a version that includes the fix for this issue.
For Sinteso Mobile versions prior to V4.3.0001, update to a version that includes the fix for this issue.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cerberus Pro Ul Engineering Tool
Cerberus Pro En Fire Panel Fc72X Ip6
Cerberus Pro En Fire Panel Fc72X Ip7
Cerberus Pro En Fire Panel Fc72X Ip8
Cerberus Pro En X200 Cloud Distribution Ip7
Cerberus Pro En X200 Cloud Distribution Ip8
Cerberus Pro En X300 Cloud Distribution Ip7
Cerberus Pro En X300 Cloud Distribution Ip8
Cerberus Pro Ul Compact Panel Fc922/924
Cerberus Pro Ul X300 Cloud Distribution
Desigo Fire Safety Ul Compact Panel Fc2025/2050
Desigo Fire Safety Ul Engineering Tool
Desigo Fire Safety Ul X300 Cloud Distribution
Sinteso Fs20 En Engineering Tool
Sinteso Fs20 En Fire Panel Fc20 Mp6
Sinteso Fs20 En Fire Panel Fc20 Mp7
Sinteso Fs20 En Fire Panel Fc20 Mp8
Sinteso Fs20 En X200 Cloud Distribution Mp7
Sinteso Fs20 En X200 Cloud Distribution Mp8
Sinteso Fs20 En X300 Cloud Distribution Mp7
Sinteso Fs20 En X300 Cloud Distribution Mp8
Sinteso Mobile