7.5
CVSSv3

CVE-2022-40227

Published: 11/10/2022 Updated: 14/10/2022
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V17 Update 4), SIMATIC HMI KTP Mobile Panels (All versions < V17 Update 4), SIMATIC HMI KTP1200 Basic (All versions < V17 Update 5), SIMATIC HMI KTP400 Basic (All versions < V17 Update 5), SIMATIC HMI KTP700 Basic (All versions < V17 Update 5), SIMATIC HMI KTP900 Basic (All versions < V17 Update 5), SIPLUS HMI KTP1200 BASIC (All versions < V17 Update 5), SIPLUS HMI KTP400 BASIC (All versions < V17 Update 5), SIPLUS HMI KTP700 BASIC (All versions < V17 Update 5), SIPLUS HMI KTP900 BASIC (All versions < V17 Update 5). Affected devices do not properly validate input sent to certain services over TCP. This could allow an unauthenticated remote malicious user to cause a permanent denial of service condition (requiring a device reboot) by sending specially crafted TCP packets.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

siemens simatic hmi comfort panels firmware

siemens simatic hmi comfort panels firmware 17.0

siemens simatic hmi ktp400 basic firmware

siemens simatic hmi ktp400 basic firmware 17.0

siemens simatic hmi ktp700 basic firmware

siemens simatic hmi ktp700 basic firmware 17.0

siemens simatic hmi ktp900 basic firmware

siemens simatic hmi ktp900 basic firmware 17.0

siemens simatic hmi ktp1200 basic firmware

siemens simatic hmi ktp1200 basic firmware 17.0

siemens simatic hmi ktp mobile panels firmware

siemens simatic hmi ktp mobile panels firmware 17.0

siemens siplus hmi ktp400 basic firmware

siemens siplus hmi ktp400 basic firmware 17.0

siemens siplus hmi ktp700 basic firmware

siemens siplus hmi ktp700 basic firmware 17.0

siemens siplus hmi ktp900 basic firmware

siemens siplus hmi ktp900 basic firmware 17.0

siemens siplus hmi ktp1200 basic firmware

siemens siplus hmi ktp1200 basic firmware 17.0