PT-2024-2314 · Siemens · Sinteso Fs20 En Fire Panel Fc20 Mp6+21

Published

2024-03-12

·

Updated

2024-05-14

·

CVE-2024-22041

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cerberus PRO EN Engineering Tool versions prior to MP4 Cerberus PRO EN Fire Panel FC72x IP6 versions prior to IP8 SR4 Cerberus PRO EN Fire Panel FC72x IP7 versions prior to IP8 SR4 Cerberus PRO EN Fire Panel FC72x IP8 versions prior to IP8 SR4 Cerberus PRO EN X200 Cloud Distribution IP7 versions prior to V4.3.5618 Cerberus PRO EN X200 Cloud Distribution IP8 versions prior to V4.3.5618 Cerberus PRO EN X300 Cloud Distribution IP7 versions prior to V4.3.5617 Cerberus PRO EN X300 Cloud Distribution IP8 versions prior to V4.3.5617 Cerberus PRO UL Compact Panel FC922/924 versions prior to MP4 Cerberus PRO UL Engineering Tool versions prior to MP4 Cerberus PRO UL X300 Cloud Distribution versions prior to V4.3.0001 Desigo Fire Safety UL Compact Panel FC2025/2050 versions prior to MP4 Desigo Fire Safety UL Engineering Tool versions prior to MP4 Desigo Fire Safety UL X300 Cloud Distribution versions prior to V4.3.0001 Sinteso FS20 EN Engineering Tool versions prior to MP4 Sinteso FS20 EN Fire Panel FC20 MP6 versions prior to MP8 SR4 Sinteso FS20 EN Fire Panel FC20 MP7 versions prior to MP8 SR4 Sinteso FS20 EN Fire Panel FC20 MP8 versions prior to MP8 SR4 Sinteso FS20 EN X200 Cloud Distribution MP7 versions prior to V4.3.5618 Sinteso FS20 EN X200 Cloud Distribution MP8 versions prior to V4.3.5618 Sinteso FS20 EN X300 Cloud Distribution MP7 versions prior to V4.3.5617 Sinteso FS20 EN X300 Cloud Distribution MP8 versions prior to V4.3.5617 Sinteso Mobile versions prior to V4.3.0001
Description The vulnerability is related to the network communication library in the affected systems, which improperly handles memory buffers when parsing X.509 certificates. This could allow an unauthenticated remote attacker to crash the network service, resulting in a denial of service. The issue is caused by a buffer overflow when analyzing X.509 certificates.
Recommendations For Cerberus PRO EN Engineering Tool versions prior to MP4, update to a version that includes the fix for this issue. For Cerberus PRO EN Fire Panel FC72x IP6 versions prior to IP8 SR4, update to a version that includes the fix for this issue. For Cerberus PRO EN Fire Panel FC72x IP7 versions prior to IP8 SR4, update to a version that includes the fix for this issue. For Cerberus PRO EN Fire Panel FC72x IP8 versions prior to IP8 SR4, update to a version that includes the fix for this issue. For Cerberus PRO EN X200 Cloud Distribution IP7 versions prior to V4.3.5618, update to a version that includes the fix for this issue. For Cerberus PRO EN X200 Cloud Distribution IP8 versions prior to V4.3.5618, update to a version that includes the fix for this issue. For Cerberus PRO EN X300 Cloud Distribution IP7 versions prior to V4.3.5617, update to a version that includes the fix for this issue. For Cerberus PRO EN X300 Cloud Distribution IP8 versions prior to V4.3.5617, update to a version that includes the fix for this issue. For Cerberus PRO UL Compact Panel FC922/924 versions prior to MP4, update to a version that includes the fix for this issue. For Cerberus PRO UL Engineering Tool versions prior to MP4, update to a version that includes the fix for this issue. For Cerberus PRO UL X300 Cloud Distribution versions prior to V4.3.0001, update to a version that includes the fix for this issue. For Desigo Fire Safety UL Compact Panel FC2025/2050 versions prior to MP4, update to a version that includes the fix for this issue. For Desigo Fire Safety UL Engineering Tool versions prior to MP4, update to a version that includes the fix for this issue. For Desigo Fire Safety UL X300 Cloud Distribution versions prior to V4.3.0001, update to a version that includes the fix for this issue. For Sinteso FS20 EN Engineering Tool versions prior to MP4, update to a version that includes the fix for this issue. For Sinteso FS20 EN Fire Panel FC20 MP6 versions prior to MP8 SR4, update to a version that includes the fix for this issue. For Sinteso FS20 EN Fire Panel FC20 MP7 versions prior to MP8 SR4, update to a version that includes the fix for this issue. For Sinteso FS20 EN Fire Panel FC20 MP8 versions prior to MP8 SR4, update to a version that includes the fix for this issue. For Sinteso FS20 EN X200 Cloud Distribution MP7 versions prior to V4.3.5618, update to a version that includes the fix for this issue. For Sinteso FS20 EN X200 Cloud Distribution MP8 versions prior to V4.3.5618, update to a version that includes the fix for this issue. For Sinteso FS20 EN X300 Cloud Distribution MP7 versions prior to V4.3.5617, update to a version that includes the fix for this issue. For Sinteso FS20 EN X300 Cloud Distribution MP8 versions prior to V4.3.5617, update to a version that includes the fix for this issue. For Sinteso Mobile versions prior to V4.3.0001, update to a version that includes the fix for this issue.

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-02248
CVE-2024-22041

Affected Products

Cerberus Pro Ul Engineering Tool
Cerberus Pro En Fire Panel Fc72X Ip6
Cerberus Pro En Fire Panel Fc72X Ip7
Cerberus Pro En Fire Panel Fc72X Ip8
Cerberus Pro En X200 Cloud Distribution Ip7
Cerberus Pro En X200 Cloud Distribution Ip8
Cerberus Pro En X300 Cloud Distribution Ip7
Cerberus Pro En X300 Cloud Distribution Ip8
Cerberus Pro Ul Compact Panel Fc922/924
Cerberus Pro Ul X300 Cloud Distribution
Desigo Fire Safety Ul Compact Panel Fc2025/2050
Desigo Fire Safety Ul Engineering Tool
Desigo Fire Safety Ul X300 Cloud Distribution
Sinteso Fs20 En Engineering Tool
Sinteso Fs20 En Fire Panel Fc20 Mp6
Sinteso Fs20 En Fire Panel Fc20 Mp7
Sinteso Fs20 En Fire Panel Fc20 Mp8
Sinteso Fs20 En X200 Cloud Distribution Mp7
Sinteso Fs20 En X200 Cloud Distribution Mp8
Sinteso Fs20 En X300 Cloud Distribution Mp7
Sinteso Fs20 En X300 Cloud Distribution Mp8
Sinteso Mobile