MEDIUM · 5.3

CVE-2022-25622

The PROFINET (PNIO) stack, when integrated with the Interniche IP stack, improperly handles internal resources for TCP segments where the minimum TCP-Header length is less than defined. This could al...

Vulnerability Description

The PROFINET (PNIO) stack, when integrated with the Interniche IP stack, improperly handles internal resources for TCP segments where the minimum TCP-Header length is less than defined. This could allow an attacker to create a denial of service condition for TCP services on affected devices by sending specially crafted TCP segments.

CVSS Score

5.3

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
LOW

Affected Products

VendorProductVersions
SiemensSimatic Cfu Diq FirmwareAll versions
SiemensSimatic Cfu Diq-
SiemensSimatic Cfu Pa FirmwareAll versions
SiemensSimatic Cfu Pa-
SiemensSimatic S7-300 Cpu FirmwareAll versions
SiemensSimatic S7-300 Cpu-
SiemensSimatic S7-400H V6 FirmwareAll versions
SiemensSimatic S7-400H V6-
SiemensSimatic S7-400 Pn\/Dp V7 FirmwareAll versions
SiemensSimatic S7-400 Pn\/Dp V7-
SiemensSimatic S7-410 V8 FirmwareAll versions
SiemensSimatic S7-410 V8-
SiemensSimatic S7-410 V10 FirmwareAll versions
SiemensSimatic S7-410 V10-
SiemensSimatic S7-1500 Cpu Firmware< 2.0.0
SiemensSimatic S7-1500 Cpu-
SiemensSimatic Tdc Cp51M1 FirmwareAll versions
SiemensSimatic Tdc Cp51M1-
SiemensSimatic Tdc Cpu555 FirmwareAll versions
SiemensSimatic Tdc Cpu555-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-25622?

CVE-2022-25622 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The PROFINET (PNIO) stack, when integrated with the Interniche IP stack, improperly handles internal resources for TCP segments where the minimum TCP-Header length is less than defined. This could al...

How severe is CVE-2022-25622?

CVE-2022-25622 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-25622?

Check the references section above for vendor advisories and patch information. Affected products include: Siemens Simatic Cfu Diq Firmware, Siemens Simatic Cfu Diq, Siemens Simatic Cfu Pa Firmware, Siemens Simatic Cfu Pa, Siemens Simatic S7-300 Cpu Firmware.