First published: Tue Dec 12 2023(Updated: )
A vulnerability has been identified in SIMATIC PC-Station Plus (All versions), SIMATIC S7-400 CPU 412-2 PN V7 (All versions), SIMATIC S7-400 CPU 414-3 PN/DP V7 (All versions), SIMATIC S7-400 CPU 414F-3 PN/DP V7 (All versions), SIMATIC S7-400 CPU 416-3 PN/DP V7 (All versions), SIMATIC S7-400 CPU 416F-3 PN/DP V7 (All versions), SINAMICS S120 (incl. SIPLUS variants) (All versions < V5.2 SP3 HF15), SIPLUS S7-400 CPU 414-3 PN/DP V7 (All versions), SIPLUS S7-400 CPU 416-3 PN/DP V7 (All versions). The affected products do not handle HTTP(S) requests to the web server correctly. This could allow an attacker to exhaust system resources and create a denial of service condition for the device.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Siemens 6ES7412-2EK07-0AB0 | ||
Siemens 6ES7412-2EK07-0AB0 Firmware | ||
All of | ||
Siemens 6ES7414-3EM07-0AB0 | ||
Siemens 6ES7414-3EM07-0AB0 Firmware | ||
All of | ||
Siemens 6ES7414-3FM07-0AB0 | ||
Siemens 6ES7414-3FM07-0AB0 Firmware | ||
All of | ||
Siemens 6ES7416-3ES07-0AB0 | ||
Siemens 6ES7416-3ES07-0AB0 Firmware | ||
All of | ||
Siemens 6ES7416-3FS07-0AB0 | ||
Siemens 6ES7416-3FS07-0AB0 Firmware | ||
All of | ||
Siemens 6AG1414-3EM07-7AB0 Firmware | ||
Siemens 6AG1414-3EM07-7AB0 Firmware | ||
All of | ||
Siemens 6AG1416-3ES07-7AB0 | ||
Siemens 6AG1416-3ES07-7AB0 Firmware | ||
All of | ||
Any of | ||
Siemens Sinamics S120 | ||
Siemens Sinamics S120 | =4.7 | |
Siemens Sinamics S120 | =4.8 | |
Siemens Sinamics S120 | =4.9 | |
Siemens Sinamics S120 | =5.0 | |
Siemens Sinamics S120 | =5.1-sp1 | |
Siemens Sinamics S120 | =5.1-sp1_hotfix1 | |
Siemens Sinamics S120 | =5.1-sp1_hotfix13 | |
Siemens Sinamics S120 | =5.2 | |
Siemens Sinamics S120 | =5.2-hotfix1 | |
Siemens Sinamics S120 | =5.2-hotfix11 | |
Siemens Sinamics S120 | =5.2-hotfix7 | |
Siemens Sinamics S120 | =5.2-sp3 | |
Siemens Sinamics S120 | =5.2-sp3_hotfix1 | |
Siemens Sinamics S120 | =5.2-sp3_hotfix13 | |
Siemens Sinamics S120 | =5.2-sp3_hotfix6 | |
Siemens Sinamics S120 | =5.2-sp3_hotfix9 | |
Siemens Sinamics S120 Firmware | ||
All of | ||
Siemens SIMATIC PC-Station Plus Firmware | ||
Siemens SIMATIC PC-Station Plus Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-47374 has been assigned a high severity rating due to its potential impact on system integrity and confidentiality.
To remediate CVE-2022-47374, users should update their Siemens firmware to the latest versions provided by the vendor.
CVE-2022-47374 affects multiple products including various versions of SIMATIC PC-Station Plus and the S7-400 series CPUs.
The risks associated with CVE-2022-47374 include unauthorized access and possible manipulation of device commands.
Yes, Siemens has released patches for CVE-2022-47374 that users are advised to implement immediately.