CVE Feed

    Dashboard / CVE / CVE-2022-25622

    CVE-2022-25622

    The PROFINET (PNIO) stack, when integrated with the Interniche IP stack, improperly handles internal resources for TCP segments where the minimum TCP-Header length is less than defined. This could allow an attacker to create a denial of service condition for TCP services on affected devices by sending specially crafted TCP segments.

    Published:Apr 12, 2022
    Last Modified:Apr 21, 2025
    EPS:Apr 12, 2022
    EPSS Score:0.00117
    CVSS Score:5.3

    Affected Products

    Vendor
    Siemens
    Product
    Simatic Cfu Diq
    Vendor
    Siemens
    Product
    Simatic Cfu Diq Firmware
    Vendor
    Siemens
    Product
    Simatic Cfu Pa
    Vendor
    Siemens
    Product
    Simatic Cfu Pa Firmware
    Vendor
    Siemens
    Product
    Simatic S7-1500 Cpu
    Vendor
    Siemens
    Product
    Simatic S7-1500 Cpu Firmware
    Vendor
    Siemens
    Product
    Simatic S7-300 Cpu
    Vendor
    Siemens
    Product
    Simatic S7-300 Cpu Firmware
    Vendor
    Siemens
    Product
    Simatic S7-400 Pn\/dp V7
    Vendor
    Siemens
    Product
    Simatic S7-400 Pn\/dp V7 Firmware
    Vendor
    Siemens
    Product
    Simatic S7-400h V6
    Vendor
    Siemens
    Product
    Simatic S7-400h V6 Firmware
    Vendor
    Siemens
    Product
    Simatic S7-410 V10
    Vendor
    Siemens
    Product
    Simatic S7-410 V10 Firmware
    Vendor
    Siemens
    Product
    Simatic S7-410 V8
    Vendor
    Siemens
    Product
    Simatic S7-410 V8 Firmware
    Vendor
    Siemens
    Product
    Simatic Tdc Cp51m1
    Vendor
    Siemens
    Product
    Simatic Tdc Cp51m1 Firmware
    Vendor
    Siemens
    Product
    Simatic Tdc Cpu555
    Vendor
    Siemens
    Product
    Simatic Tdc Cpu555 Firmware
    Vendor
    Siemens
    Product
    Simatic Winac Rtx
    Vendor
    Siemens
    Product
    Simatic Winac Rtx Firmware
    Vendor
    Siemens
    Product
    Simit Simulation Platform

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High