CVE-2022-34819

high-risk
Published 2022-07-12

A vulnerability has been identified in SIMATIC CP 1242-7 V2 (All versions < V3.3.46), SIMATIC CP 1243-1 (All versions < V3.3.46), SIMATIC CP 1243-7 LTE EU (All versions < V3.3.46), SIMATIC CP 1243-7 LTE US (All versions < V3.3.46), SIMATIC CP 1243-8 IRC (All versions < V3.3.46), SIMATIC CP 1542SP-1 IRC (All versions >= V2.0 < V2.2.28), SIMATIC CP 1543-1 (All versions < V3.0.22), SIMATIC CP 1543SP-1 (All versions >= V2.0 < V2.2.28), SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL (All versions >= V2.0 < V2.2.28), SIPLUS ET 200SP CP 1543SP-1 ISEC (All versions >= V2.0 < V2.2.28), SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL (All versions >= V2.0 < V2.2.28), SIPLUS NET CP 1242-7 V2 (All versions < V3.3.46), SIPLUS NET CP 1543-1 (All versions < V3.0.22), SIPLUS S7-1200 CP 1243-1 (All versions < V3.3.46), SIPLUS S7-1200 CP 1243-1 RAIL (All versions < V3.3.46). The application lacks proper validation of user-supplied data when parsing specific messages. This could result in a heap-based buffer overflow. An attacker could leverage this vulnerability to execute code in the context of device.

Do I need to act?

~
1.5% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
10
CVSS 10.0/10 Critical
NETWORK / LOW complexity

Affected Products (15)

Simatic Cp 1242-7 V2 Firmware
Simatic Cp 1243-1 Firmware
Simatic Cp 1243-7 Lte Eu Firmware
Simatic Cp 1243-7 Lte Us Firmware
Simatic Cp 1243-8 Irc Firmware
Simatic Cp 1542Sp-1 Irc Firmware
Simatic Cp 1543Sp-1 Firmware
Siplus Et 200Sp Cp 1542Sp-1 Irc Tx Rail Firmware
Siplus Et 200Sp Cp 1543Sp-1 Isec Firmware
Siplus Et 200Sp Cp 1543Sp-1 Isec Tx Rail Firmware
Siplus Net Cp 1242-7 V2 Firmware
Siplus S7-1200 Cp 1243-1 Firmware
Siplus S7-1200 Cp 1243-1 Rail Firmware

Affected Vendors

55
/ 100
high-risk
Severity 33/34 · Critical
Exploitability 4/34 · Minimal
Exposure 18/34 · Moderate