First published: Tue Oct 11 2022(Updated: )
A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V17 Update 4), SIMATIC HMI KTP Mobile Panels (All versions < V17 Update 4), SIMATIC HMI KTP1200 Basic (All versions < V17 Update 5), SIMATIC HMI KTP400 Basic (All versions < V17 Update 5), SIMATIC HMI KTP700 Basic (All versions < V17 Update 5), SIMATIC HMI KTP900 Basic (All versions < V17 Update 5), SIPLUS HMI KTP1200 BASIC (All versions < V17 Update 5), SIPLUS HMI KTP400 BASIC (All versions < V17 Update 5), SIPLUS HMI KTP700 BASIC (All versions < V17 Update 5), SIPLUS HMI KTP900 BASIC (All versions < V17 Update 5). Affected devices do not properly validate input sent to certain services over TCP. This could allow an unauthenticated remote attacker to cause a permanent denial of service condition (requiring a device reboot) by sending specially crafted TCP packets.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens SIMATIC HMI Panel firmware | <17.0 | |
Siemens SIMATIC HMI Panel firmware | =17.0 | |
Siemens SIMATIC HMI Panel firmware | =17.0-update1 | |
Siemens SIMATIC HMI Panel firmware | =17.0-update2 | |
Siemens SIMATIC HMI Panel firmware | =17.0-update3 | |
Siemens SIMATIC HMI Comfort Panel | ||
Siemens SIMATIC HMI KTP400 Basic | <17.0 | |
Siemens SIMATIC HMI KTP400 Basic | =17.0 | |
Siemens SIMATIC HMI KTP400 Basic | =17.0-udpate1 | |
Siemens SIMATIC HMI KTP400 Basic | =17.0-update2 | |
Siemens SIMATIC HMI KTP400 Basic | =17.0-update3 | |
Siemens SIMATIC HMI KTP400 Basic | =17.0-update4 | |
Siemens SIMATIC HMI KTP400 Basic firmware | ||
Siemens SIMATIC HMI KTP700 Basic | <17.0 | |
Siemens SIMATIC HMI KTP700 Basic | =17.0 | |
Siemens SIMATIC HMI KTP700 Basic | =17.0-udpate1 | |
Siemens SIMATIC HMI KTP700 Basic | =17.0-update2 | |
Siemens SIMATIC HMI KTP700 Basic | =17.0-update3 | |
Siemens SIMATIC HMI KTP700 Basic | =17.0-update4 | |
Siemens SIMATIC HMI KTP700 Basic | ||
Siemens SIMATIC HMI KTP900 Basic | <17.0 | |
Siemens SIMATIC HMI KTP900 Basic | =17.0 | |
Siemens SIMATIC HMI KTP900 Basic | =17.0-udpate1 | |
Siemens SIMATIC HMI KTP900 Basic | =17.0-update2 | |
Siemens SIMATIC HMI KTP900 Basic | =17.0-update3 | |
Siemens SIMATIC HMI KTP900 Basic | =17.0-update4 | |
Siemens SIMATIC HMI KTP900 Basic | ||
Siemens SIPLUS HMI KTP1200 Basic firmware | <17.0 | |
Siemens SIPLUS HMI KTP1200 Basic firmware | =17.0 | |
Siemens SIPLUS HMI KTP1200 Basic firmware | =17.0-udpate1 | |
Siemens SIPLUS HMI KTP1200 Basic firmware | =17.0-update2 | |
Siemens SIPLUS HMI KTP1200 Basic firmware | =17.0-update3 | |
Siemens SIPLUS HMI KTP1200 Basic firmware | =17.0-update4 | |
Siemens SIPLUS HMI KTP1200 Basic | ||
Siemens SIMATIC HMI KTP Mobile Panels Firmware | <17.0 | |
Siemens SIMATIC HMI KTP Mobile Panels Firmware | =17.0 | |
Siemens SIMATIC HMI KTP Mobile Panels Firmware | =17.0-udpate1 | |
Siemens SIMATIC HMI KTP Mobile Panels Firmware | =17.0-update2 | |
Siemens SIMATIC HMI KTP Mobile Panels Firmware | =17.0-update3 | |
Siemens SIMATIC HMI Mobile Panels firmware | ||
Siemens SIPLUS HMI KTP400 Basic | <17.0 | |
Siemens SIPLUS HMI KTP400 Basic | =17.0 | |
Siemens SIPLUS HMI KTP400 Basic | =17.0-udpate1 | |
Siemens SIPLUS HMI KTP400 Basic | =17.0-update2 | |
Siemens SIPLUS HMI KTP400 Basic | =17.0-update3 | |
Siemens SIPLUS HMI KTP400 Basic | =17.0-update4 | |
Siemens SIMATIC HMI KTP400 Basic | ||
Siemens SIPLUS HMI KTP700 Basic | <17.0 | |
Siemens SIPLUS HMI KTP700 Basic | =17.0 | |
Siemens SIPLUS HMI KTP700 Basic | =17.0-udpate1 | |
Siemens SIPLUS HMI KTP700 Basic | =17.0-update2 | |
Siemens SIPLUS HMI KTP700 Basic | =17.0-update3 | |
Siemens SIPLUS HMI KTP700 Basic | =17.0-update4 | |
Siemens SIMATIC HMI KTP700 Basic | ||
Siemens SIPLUS HMI KTP900 Basic firmware | <17.0 | |
Siemens SIPLUS HMI KTP900 Basic firmware | =17.0 | |
Siemens SIPLUS HMI KTP900 Basic firmware | =17.0-udpate1 | |
Siemens SIPLUS HMI KTP900 Basic firmware | =17.0-update2 | |
Siemens SIPLUS HMI KTP900 Basic firmware | =17.0-update3 | |
Siemens SIPLUS HMI KTP900 Basic firmware | =17.0-update4 | |
Siemens SIPLUS HMI KTP900 Basic firmware | ||
Siemens SIPLUS HMI KTP1200 Basic | <17.0 | |
Siemens SIPLUS HMI KTP1200 Basic | =17.0 | |
Siemens SIPLUS HMI KTP1200 Basic | =17.0-udpate1 | |
Siemens SIPLUS HMI KTP1200 Basic | =17.0-update2 | |
Siemens SIPLUS HMI KTP1200 Basic | =17.0-update3 | |
Siemens SIPLUS HMI KTP1200 Basic | =17.0-update4 | |
Siemens SIPLUS HMI KTP1200 Basic firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-40227 is categorized as high, indicating significant risk for systems that are affected.
To fix CVE-2022-40227, it is recommended to upgrade to the latest firmware version V17 Update 4 or later for affected devices.
CVE-2022-40227 affects various Siemens SIMATIC HMI Comfort Panels, KTP Mobile Panels, and KTP basic models on versions below V17 Update 4.
Exploitation of CVE-2022-40227 could enable unauthorized access and control of the devices, potentially leading to system disruption.
Yes, Siemens devices running on firmware versions V17 Update 4 and later are not vulnerable to CVE-2022-40227.