CVE-2022-34820
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability has been identified in SIMATIC CP 1242-7 V2 (All versions < V3.3.46), SIMATIC CP 1243-1 (All versions < V3.3.46), SIMATIC CP 1243-7 LTE EU (All versions < V3.3.46), SIMATIC CP 1243-7 LTE US (All versions < V3.3.46), SIMATIC CP 1243-8 IRC (All versions < V3.3.46), SIMATIC CP 1542SP-1 IRC (All versions >= V2.0 < V2.2.28), SIMATIC CP 1543-1 (All versions < V3.0.22), SIMATIC CP 1543SP-1 (All versions >= V2.0 < V2.2.28), SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL (All versions >= V2.0 < V2.2.28), SIPLUS ET 200SP CP 1543SP-1 ISEC (All versions >= V2.0 < V2.2.28), SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL (All versions >= V2.0 < V2.2.28), SIPLUS NET CP 1242-7 V2 (All versions < V3.3.46), SIPLUS NET CP 1543-1 (All versions < V3.0.22), SIPLUS S7-1200 CP 1243-1 (All versions < V3.3.46), SIPLUS S7-1200 CP 1243-1 RAIL (All versions < V3.3.46). The application does not correctly escape some user provided fields during the authentication process. This could allow an attacker to inject custom commands and execute arbitrary code with elevated privileges.
Se ha identificado una vulnerabilidad en SIMATIC CP 1242-7 V2 (Todas las versiones anteriores a V3.3.46), SIMATIC CP 1243-1 (Todas las versiones anteriores a V3.3.46), SIMATIC CP 1243-7 LTE EU (Todas las versiones anteriores a V3.3.46), SIMATIC CP 1243-7 LTE US (Todas las versiones anteriores a V3. 3.46), SIMATIC CP 1243-8 IRC (Todas las versiones anteriores a V3.3.46), SIMATIC CP 1542SP-1 IRC (Todas las versiones posteriores o iguales a V2.0), SIMATIC CP 1543-1 (Todas las versiones anteriores a V3.0.22), SIMATIC CP 1543SP-1 (Todas las versiones posteriores o iguales a V2. 0), SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL (Todas las versiones posteriores o iguales a V2.0), SIPLUS ET 200SP CP 1543SP-1 ISEC (Todas las versiones posteriores o iguales a V2.0), SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL (Todas las versiones posteriores o iguales a V2. 0), SIPLUS NET CP 1242-7 V2 (Todas las versiones anteriores a V3.3.46), SIPLUS NET CP 1543-1 (Todas las versiones anteriores a V3.0.22), SIPLUS S7-1200 CP 1243-1 (Todas las versiones anteriores a V3.3.46), SIPLUS S7-1200 CP 1243-1 RAIL (Todas las versiones anteriores a V3.3.46). La aplicación no escapa correctamente de algunos campos proporcionados por el usuario durante el proceso de autenticación. Esto podría permitir a un atacante inyectar comandos personalizados y ejecutar código arbitrario con privilegios elevados
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-06-29 CVE Reserved
- 2022-07-12 CVE Published
- 2024-02-02 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
- CWE-116: Improper Encoding or Escaping of Output
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-517377.pdf | 2023-06-29 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Siemens Search vendor "Siemens" | Simatic Cp 1242-7 V2 Firmware Search vendor "Siemens" for product "Simatic Cp 1242-7 V2 Firmware" | < 3.3.46 Search vendor "Siemens" for product "Simatic Cp 1242-7 V2 Firmware" and version " < 3.3.46" | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Cp 1242-7 V2 Search vendor "Siemens" for product "Simatic Cp 1242-7 V2" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Cp 1243-1 Firmware Search vendor "Siemens" for product "Simatic Cp 1243-1 Firmware" | < 3.3.46 Search vendor "Siemens" for product "Simatic Cp 1243-1 Firmware" and version " < 3.3.46" | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Cp 1243-1 Search vendor "Siemens" for product "Simatic Cp 1243-1" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Cp 1243-7 Lte Eu Firmware Search vendor "Siemens" for product "Simatic Cp 1243-7 Lte Eu Firmware" | < 3.3.46 Search vendor "Siemens" for product "Simatic Cp 1243-7 Lte Eu Firmware" and version " < 3.3.46" | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Cp 1243-7 Lte Eu Search vendor "Siemens" for product "Simatic Cp 1243-7 Lte Eu" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Cp 1243-7 Lte Us Firmware Search vendor "Siemens" for product "Simatic Cp 1243-7 Lte Us Firmware" | < 3.3.46 Search vendor "Siemens" for product "Simatic Cp 1243-7 Lte Us Firmware" and version " < 3.3.46" | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Cp 1243-7 Lte Us Search vendor "Siemens" for product "Simatic Cp 1243-7 Lte Us" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Cp 1243-8 Irc Firmware Search vendor "Siemens" for product "Simatic Cp 1243-8 Irc Firmware" | < 3.3.46 Search vendor "Siemens" for product "Simatic Cp 1243-8 Irc Firmware" and version " < 3.3.46" | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Cp 1243-8 Irc Search vendor "Siemens" for product "Simatic Cp 1243-8 Irc" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Cp 1542sp-1 Irc Firmware Search vendor "Siemens" for product "Simatic Cp 1542sp-1 Irc Firmware" | >= 2.0 < 2.2.28 Search vendor "Siemens" for product "Simatic Cp 1542sp-1 Irc Firmware" and version " >= 2.0 < 2.2.28" | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Cp 1542sp-1 Irc Search vendor "Siemens" for product "Simatic Cp 1542sp-1 Irc" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Cp 1543-1 Firmware Search vendor "Siemens" for product "Simatic Cp 1543-1 Firmware" | < 3.0.22 Search vendor "Siemens" for product "Simatic Cp 1543-1 Firmware" and version " < 3.0.22" | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Cp 1543-1 Search vendor "Siemens" for product "Simatic Cp 1543-1" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Simatic Cp 1543sp-1 Firmware Search vendor "Siemens" for product "Simatic Cp 1543sp-1 Firmware" | >= 2.0 < 2.2.28 Search vendor "Siemens" for product "Simatic Cp 1543sp-1 Firmware" and version " >= 2.0 < 2.2.28" | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic Cp 1543sp-1 Search vendor "Siemens" for product "Simatic Cp 1543sp-1" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Siplus Et 200sp Cp 1542sp-1 Irc Tx Rail Firmware Search vendor "Siemens" for product "Siplus Et 200sp Cp 1542sp-1 Irc Tx Rail Firmware" | >= 2.0 < 2.2.28 Search vendor "Siemens" for product "Siplus Et 200sp Cp 1542sp-1 Irc Tx Rail Firmware" and version " >= 2.0 < 2.2.28" | - |
Affected
| in | Siemens Search vendor "Siemens" | Siplus Et 200sp Cp 1542sp-1 Irc Tx Rail Search vendor "Siemens" for product "Siplus Et 200sp Cp 1542sp-1 Irc Tx Rail" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Siplus Et 200sp Cp 1543sp-1 Isec Firmware Search vendor "Siemens" for product "Siplus Et 200sp Cp 1543sp-1 Isec Firmware" | >= 2.0 < 2.2.28 Search vendor "Siemens" for product "Siplus Et 200sp Cp 1543sp-1 Isec Firmware" and version " >= 2.0 < 2.2.28" | - |
Affected
| in | Siemens Search vendor "Siemens" | Siplus Et 200sp Cp 1543sp-1 Isec Search vendor "Siemens" for product "Siplus Et 200sp Cp 1543sp-1 Isec" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Siplus Et 200sp Cp 1543sp-1 Isec Tx Rail Firmware Search vendor "Siemens" for product "Siplus Et 200sp Cp 1543sp-1 Isec Tx Rail Firmware" | >= 2.0 < 2.2.28 Search vendor "Siemens" for product "Siplus Et 200sp Cp 1543sp-1 Isec Tx Rail Firmware" and version " >= 2.0 < 2.2.28" | - |
Affected
| in | Siemens Search vendor "Siemens" | Siplus Et 200sp Cp 1543sp-1 Isec Tx Rail Search vendor "Siemens" for product "Siplus Et 200sp Cp 1543sp-1 Isec Tx Rail" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Siplus Net Cp 1242-7 V2 Firmware Search vendor "Siemens" for product "Siplus Net Cp 1242-7 V2 Firmware" | < 3.3.46 Search vendor "Siemens" for product "Siplus Net Cp 1242-7 V2 Firmware" and version " < 3.3.46" | - |
Affected
| in | Siemens Search vendor "Siemens" | Siplus Net Cp 1242-7 V2 Search vendor "Siemens" for product "Siplus Net Cp 1242-7 V2" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Siplus Net Cp 1543-1 Firmware Search vendor "Siemens" for product "Siplus Net Cp 1543-1 Firmware" | < 3.0.22 Search vendor "Siemens" for product "Siplus Net Cp 1543-1 Firmware" and version " < 3.0.22" | - |
Affected
| in | Siemens Search vendor "Siemens" | Siplus Net Cp 1543-1 Search vendor "Siemens" for product "Siplus Net Cp 1543-1" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Siplus S7-1200 Cp 1243-1 Firmware Search vendor "Siemens" for product "Siplus S7-1200 Cp 1243-1 Firmware" | < 3.3.46 Search vendor "Siemens" for product "Siplus S7-1200 Cp 1243-1 Firmware" and version " < 3.3.46" | - |
Affected
| in | Siemens Search vendor "Siemens" | Siplus S7-1200 Cp 1243-1 Search vendor "Siemens" for product "Siplus S7-1200 Cp 1243-1" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Siplus S7-1200 Cp 1243-1 Rail Firmware Search vendor "Siemens" for product "Siplus S7-1200 Cp 1243-1 Rail Firmware" | < 3.3.46 Search vendor "Siemens" for product "Siplus S7-1200 Cp 1243-1 Rail Firmware" and version " < 3.3.46" | - |
Affected
| in | Siemens Search vendor "Siemens" | Siplus S7-1200 Cp 1243-1 Rail Search vendor "Siemens" for product "Siplus S7-1200 Cp 1243-1 Rail" | - | - |
Safe
|