CVE-2022-27194

Description

A vulnerability has been identified in SIMATIC PCS neo (Administration Console) (All versions < V3.1 SP1), SINETPLAN (All versions), TIA Portal (V15, V15.1, V16 and V17). The affected system cannot properly process specially crafted packets sent to port 8888/tcp. A remote attacker could exploit this vulnerability to cause a Denial-of-Service condition. The affected devices must be restarted manually.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.161

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2019-10934,CVE-2020-25238,CVE-2022-27194,CVE-2023-30757 are affected in Siemens Totally Integrated Automation Portal (TIA Portal) 15.1Windows
Multiple Vulnerabilities are affected in Siemens Totally Integrated Automation Portal (TIA Portal) 16Windows
Multiple Vulnerabilities are affected in Siemens Totally Integrated Automation Portal (TIA Portal) 15Windows
Multiple Vulnerabilities are affected in Siemens SIMATIC PCS neo 3.0--Windows
Vulnerabilities CVE-2022-27194 are affected in Siemens SIMATIC PCS neo 3.1Windows
Multiple Vulnerabilities are affected in Siemens Totally Integrated Automation Portal (TIA Portal) 17Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234