CVE-2022-27481: Race Condition
A vulnerability has been identified in SCALANCE W1788-1 M12 (All versions < V3.0.0), SCALANCE W1788-2 EEC M12 (All versions < V3.0.0), SCALANCE W1788-2 M12 (All versions < V3.0.0), SCALANCE W1788-2IA M12 (All versions < V3.0.0). Affected devices do not properly handle resources of ARP requests. This could allow an attacker to cause a race condition that leads to a crash of the entire device.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-27481?
The severity of CVE-2022-27481 is medium with a CVSS score of 5.3.
Which devices are affected by CVE-2022-27481?
SCALANCE W1788-1 M12, SCALANCE W1788-2 EEC M12, SCALANCE W1788-2 M12, and SCALANCE W1788-2IA M12 are affected by CVE-2022-27481.
What is the vulnerability description of CVE-2022-27481?
CVE-2022-27481 is a vulnerability in SCALANCE W1788-1 M12, SCALANCE W1788-2 EEC M12, SCALANCE W1788-2 M12, and SCALANCE W1788-2IA M12 devices where affected devices do not properly handle resources of ARP requests.
How can I fix CVE-2022-27481?
There is no fix available at the moment. It is recommended to follow the guidance provided by Siemens in their advisory.
Where can I find more information about CVE-2022-27481?
You can find more information about CVE-2022-27481 in the Siemens Product CERT advisory.