CVE-2022-47375
A vulnerability has been identified in SIMATIC PC-Station Plus (All versions), SIMATIC S7-400 CPU 412-2 PN V7 (All versions), SIMATIC S7-400 CPU 414-3 PN/DP V7 (All versions), SIMATIC S7-400 CPU 414F-3 PN/DP V7 (All versions), SIMATIC S7-400 CPU 416-3 PN/DP V7 (All versions), SIMATIC S7-400 CPU 416F-3 PN/DP V7 (All versions), SINAMICS S120 (incl. SIPLUS variants) (All versions < V5.2 SP3 HF15), SIPLUS S7-400 CPU 414-3 PN/DP V7 (All versions), SIPLUS S7-400 CPU 416-3 PN/DP V7 (All versions). The affected products do not handle long file names correctly. This could allow an attacker to create a buffer overflow and create a denial of service condition for the device.
Published:Dec 12, 2023
Last Modified:Nov 21, 2024
EPS:Dec 12, 2023
EPSS Score:0.00302
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Siemens
Product
6ag1414-3em07-7ab0
Siemens
6ag1414-3em07-7ab0
Vendor
Siemens
Product
6ag1414-3em07-7ab0 Firmware
Siemens
6ag1414-3em07-7ab0 Firmware
Vendor
Siemens
Product
6ag1416-3es07-7ab0
Siemens
6ag1416-3es07-7ab0
Vendor
Siemens
Product
6ag1416-3es07-7ab0 Firmware
Siemens
6ag1416-3es07-7ab0 Firmware
Vendor
Siemens
Product
6es7412-2ek07-0ab0
Siemens
6es7412-2ek07-0ab0
Vendor
Siemens
Product
6es7412-2ek07-0ab0 Firmware
Siemens
6es7412-2ek07-0ab0 Firmware
Vendor
Siemens
Product
6es7414-3em07-0ab0
Siemens
6es7414-3em07-0ab0
Vendor
Siemens
Product
6es7414-3em07-0ab0 Firmware
Siemens
6es7414-3em07-0ab0 Firmware
Vendor
Siemens
Product
6es7414-3fm07-0ab0
Siemens
6es7414-3fm07-0ab0
Vendor
Siemens
Product
6es7414-3fm07-0ab0 Firmware
Siemens
6es7414-3fm07-0ab0 Firmware
Vendor
Siemens
Product
6es7416-3es07-0ab0
Siemens
6es7416-3es07-0ab0
Vendor
Siemens
Product
6es7416-3es07-0ab0 Firmware
Siemens
6es7416-3es07-0ab0 Firmware
Vendor
Siemens
Product
6es7416-3fs07-0ab0
Siemens
6es7416-3fs07-0ab0
Vendor
Siemens
Product
6es7416-3fs07-0ab0 Firmware
Siemens
6es7416-3fs07-0ab0 Firmware
Vendor
Siemens
Product
Simatic Pc-station Plus
Siemens
Simatic Pc-station Plus
Vendor
Siemens
Product
Simatic Pc-station Plus Firmware
Siemens
Simatic Pc-station Plus Firmware
Vendor
Siemens
Product
Sinamics S120
Siemens
Sinamics S120
Vendor
Siemens
Product
Sinamics S120 Firmware
Siemens
Sinamics S120 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
