CVE-2022-40227

high-risk
Published 2022-10-11

A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V17 Update 4), SIMATIC HMI KTP Mobile Panels (All versions < V17 Update 4), SIMATIC HMI KTP1200 Basic (All versions < V17 Update 5), SIMATIC HMI KTP400 Basic (All versions < V17 Update 5), SIMATIC HMI KTP700 Basic (All versions < V17 Update 5), SIMATIC HMI KTP900 Basic (All versions < V17 Update 5), SIPLUS HMI KTP1200 BASIC (All versions < V17 Update 5), SIPLUS HMI KTP400 BASIC (All versions < V17 Update 5), SIPLUS HMI KTP700 BASIC (All versions < V17 Update 5), SIPLUS HMI KTP900 BASIC (All versions < V17 Update 5). Affected devices do not properly validate input sent to certain services over TCP. This could allow an unauthenticated remote attacker to cause a permanent denial of service condition (requiring a device reboot) by sending specially crafted TCP packets.

Do I need to act?

-
0.10% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10 High
NETWORK / LOW complexity

Affected Products (20)

Simatic Hmi Comfort Panels Firmware
Simatic Hmi Comfort Panels Firmware
Simatic Hmi Comfort Panels Firmware
Simatic Hmi Comfort Panels Firmware
Simatic Hmi Comfort Panels Firmware
Simatic Hmi Ktp400 Basic Firmware
Simatic Hmi Ktp400 Basic Firmware
Simatic Hmi Ktp400 Basic Firmware
Simatic Hmi Ktp400 Basic Firmware
Simatic Hmi Ktp400 Basic Firmware
Simatic Hmi Ktp400 Basic Firmware
Simatic Hmi Ktp700 Basic Firmware
Simatic Hmi Ktp700 Basic Firmware
Simatic Hmi Ktp700 Basic Firmware
Simatic Hmi Ktp700 Basic Firmware
Simatic Hmi Ktp700 Basic Firmware
Simatic Hmi Ktp700 Basic Firmware
Simatic Hmi Ktp900 Basic Firmware
Simatic Hmi Ktp900 Basic Firmware
Simatic Hmi Ktp900 Basic Firmware

Affected Vendors

53
/ 100
high-risk
Severity 26/34 · High
Exploitability 0/34 · Minimal
Exposure 27/34 · High