CVE-2022-30938: Buffer Overflow
A vulnerability has been identified in EN100 Ethernet module DNP3 IP variant (All versions), EN100 Ethernet module IEC 104 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.40), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module PROFINET IO variant (All versions). Affected applications contains a memory corruption vulnerability while parsing specially crafted HTTP packets to /txtrace endpoint manupulating a specific argument. This could allow an attacker to crash the affected application leading to a denial of service condition
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-30938.
What is the severity of CVE-2022-30938?
The severity of CVE-2022-30938 is high with a severity value of 7.5.
Which Siemens products are affected by CVE-2022-30938?
The Siemens products affected by CVE-2022-30938 are EN100 Ethernet module DNP3 IP variant (All versions), EN100 Ethernet module IEC 104 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.40), EN100 Ethernet module Modbus TCP variant (All versions), and EN100 Ethernet module PROFINET IO variant (All versions).
Is Siemens En100 Ethernet Module vulnerable to CVE-2022-30938?
Siemens En100 Ethernet Module is not vulnerable to CVE-2022-30938.
How can I fix CVE-2022-30938?
To fix CVE-2022-30938, apply the necessary patches or firmware updates provided by Siemens.