// For flags

CVE-2022-43716

 

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Attend
*SSVC
Descriptions

A vulnerability has been identified in SIMATIC CP 1242-7 V2 (All versions), SIMATIC CP 1243-1 (All versions), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions), SIMATIC CP 1243-7 LTE EU (All versions), SIMATIC CP 1243-7 LTE US (All versions), SIMATIC CP 1243-8 IRC (All versions), SIMATIC CP 1542SP-1 (All versions), SIMATIC CP 1542SP-1 IRC (All versions), SIMATIC CP 1543SP-1 (All versions), SIMATIC CP 443-1 (All versions < V3.3), SIMATIC CP 443-1 (All versions < V3.3), SIMATIC CP 443-1 Advanced (All versions < V3.3), SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL (All versions), SIPLUS ET 200SP CP 1543SP-1 ISEC (All versions), SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL (All versions), SIPLUS NET CP 1242-7 V2 (All versions), SIPLUS NET CP 443-1 (All versions < V3.3), SIPLUS NET CP 443-1 Advanced (All versions < V3.3), SIPLUS S7-1200 CP 1243-1 (All versions), SIPLUS S7-1200 CP 1243-1 RAIL (All versions), SIPLUS TIM 1531 IRC (All versions < V2.3.6), TIM 1531 IRC (All versions < V2.3.6). The webserver of the affected products contains a vulnerability that may lead to a denial of service condition. An attacker may cause a denial of service situation which leads to a restart of the webserver of the affected product.

A vulnerability has been identified in SIMATIC CP 1242-7 V2 (6GK7242-7KX31-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 (6GK7243-1BX30-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.4.29), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions < V3.4.29), SIMATIC CP 1243-7 LTE EU (6GK7243-7KX30-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-7 LTE US (6GK7243-7SX30-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-8 IRC (6GK7243-8RX30-0XE0) (All versions < V3.4.29), SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0) (All versions < V2.3), SIMATIC CP 1542SP-1 IRC (6GK7542-6VX00-0XE0) (All versions < V2.3), SIMATIC CP 1543SP-1 (6GK7543-6WX00-0XE0) (All versions < V2.3), SIMATIC CP 443-1 (6GK7443-1EX30-0XE0) (All versions < V3.3), SIMATIC CP 443-1 (6GK7443-1EX30-0XE1) (All versions < V3.3), SIMATIC CP 443-1 Advanced (6GK7443-1GX30-0XE0) (All versions < V3.3), SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL (6AG2542-6VX00-4XE0) (All versions < V2.3), SIPLUS ET 200SP CP 1543SP-1 ISEC (6AG1543-6WX00-7XE0) (All versions < V2.3), SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL (6AG2543-6WX00-4XE0) (All versions < V2.3), SIPLUS NET CP 1242-7 V2 (6AG1242-7KX31-7XE0) (All versions < V3.4.29), SIPLUS NET CP 443-1 (6AG1443-1EX30-4XE0) (All versions < V3.3), SIPLUS NET CP 443-1 Advanced (6AG1443-1GX30-4XE0) (All versions < V3.3), SIPLUS S7-1200 CP 1243-1 (6AG1243-1BX30-2AX0) (All versions < V3.4.29), SIPLUS S7-1200 CP 1243-1 RAIL (6AG2243-1BX30-1XE0) (All versions < V3.4.29), SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0) (All versions < V2.3.6), TIM 1531 IRC (6GK7543-1MX00-0XE0) (All versions < V2.3.6). The webserver of the affected products contains a vulnerability that may lead to a denial of service condition. An attacker may cause a denial of service situation which leads to a restart of the webserver of the affected product.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:Attend
Exploitation
None
Automatable
Yes
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2022-10-24 CVE Reserved
  • 2023-04-11 CVE Published
  • 2024-09-10 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-416: Use After Free
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Siemens
Search vendor "Siemens"
Simatic Cp 1242-7 V2 Firmware
Search vendor "Siemens" for product "Simatic Cp 1242-7 V2 Firmware"
*-
Affected
in Siemens
Search vendor "Siemens"
Simatic Cp 1242-7 V2
Search vendor "Siemens" for product "Simatic Cp 1242-7 V2"
--
Safe
Siemens
Search vendor "Siemens"
Simatic Cp 1243-1 Firmware
Search vendor "Siemens" for product "Simatic Cp 1243-1 Firmware"
*-
Affected
in Siemens
Search vendor "Siemens"
Simatic Cp 1243-1
Search vendor "Siemens" for product "Simatic Cp 1243-1"
--
Safe
Siemens
Search vendor "Siemens"
Simatic Cp 1243-1 Dnp3 Firmware
Search vendor "Siemens" for product "Simatic Cp 1243-1 Dnp3 Firmware"
*-
Affected
in Siemens
Search vendor "Siemens"
Simatic Cp 1243-1 Dnp3
Search vendor "Siemens" for product "Simatic Cp 1243-1 Dnp3"
--
Safe
Siemens
Search vendor "Siemens"
Simatic Cp 1243-1 Iec Firmware
Search vendor "Siemens" for product "Simatic Cp 1243-1 Iec Firmware"
*-
Affected
in Siemens
Search vendor "Siemens"
Simatic Cp 1243-1 Iec
Search vendor "Siemens" for product "Simatic Cp 1243-1 Iec"
--
Safe
Siemens
Search vendor "Siemens"
Simatic Cp 1243-7 Lte Eu Firmware
Search vendor "Siemens" for product "Simatic Cp 1243-7 Lte Eu Firmware"
*-
Affected
in Siemens
Search vendor "Siemens"
Simatic Cp 1243-7 Lte Eu
Search vendor "Siemens" for product "Simatic Cp 1243-7 Lte Eu"
--
Safe
Siemens
Search vendor "Siemens"
Simatic Cp 1243-7 Lte Us Firmware
Search vendor "Siemens" for product "Simatic Cp 1243-7 Lte Us Firmware"
*-
Affected
in Siemens
Search vendor "Siemens"
Simatic Cp 1243-7 Lte Us
Search vendor "Siemens" for product "Simatic Cp 1243-7 Lte Us"
--
Safe
Siemens
Search vendor "Siemens"
Simatic Cp 1243-8 Irc Firmware
Search vendor "Siemens" for product "Simatic Cp 1243-8 Irc Firmware"
*-
Affected
in Siemens
Search vendor "Siemens"
Simatic Cp 1243-8 Irc
Search vendor "Siemens" for product "Simatic Cp 1243-8 Irc"
--
Safe
Siemens
Search vendor "Siemens"
Simatic Cp 1542sp-1 Firmware
Search vendor "Siemens" for product "Simatic Cp 1542sp-1 Firmware"
*-
Affected
in Siemens
Search vendor "Siemens"
Simatic Cp 1542sp-1
Search vendor "Siemens" for product "Simatic Cp 1542sp-1"
--
Safe
Siemens
Search vendor "Siemens"
Simatic Cp 1542sp-1 Irc Firmware
Search vendor "Siemens" for product "Simatic Cp 1542sp-1 Irc Firmware"
*-
Affected
in Siemens
Search vendor "Siemens"
Simatic Cp 1542sp-1 Irc
Search vendor "Siemens" for product "Simatic Cp 1542sp-1 Irc"
--
Safe
Siemens
Search vendor "Siemens"
Simatic Cp 1543sp-1 Firmware
Search vendor "Siemens" for product "Simatic Cp 1543sp-1 Firmware"
*-
Affected
in Siemens
Search vendor "Siemens"
Simatic Cp 1543sp-1
Search vendor "Siemens" for product "Simatic Cp 1543sp-1"
--
Safe
Siemens
Search vendor "Siemens"
Simatic Cp 443-1 Firmware
Search vendor "Siemens" for product "Simatic Cp 443-1 Firmware"
< 3.3
Search vendor "Siemens" for product "Simatic Cp 443-1 Firmware" and version " < 3.3"
-
Affected
in Siemens
Search vendor "Siemens"
Simatic Cp 443-1
Search vendor "Siemens" for product "Simatic Cp 443-1"
--
Safe
Siemens
Search vendor "Siemens"
Simatic Cp 443-1 Advanced Firmware
Search vendor "Siemens" for product "Simatic Cp 443-1 Advanced Firmware"
< 3.3
Search vendor "Siemens" for product "Simatic Cp 443-1 Advanced Firmware" and version " < 3.3"
-
Affected
in Siemens
Search vendor "Siemens"
Simatic Cp 443-1 Advanced
Search vendor "Siemens" for product "Simatic Cp 443-1 Advanced"
--
Safe
Siemens
Search vendor "Siemens"
Simatic Ipc Diagbase Firmware
Search vendor "Siemens" for product "Simatic Ipc Diagbase Firmware"
*-
Affected
in Siemens
Search vendor "Siemens"
Simatic Ipc Diagbase
Search vendor "Siemens" for product "Simatic Ipc Diagbase"
--
Safe
Siemens
Search vendor "Siemens"
Simatic Ipc Diagmonitor Firmware
Search vendor "Siemens" for product "Simatic Ipc Diagmonitor Firmware"
*-
Affected
in Siemens
Search vendor "Siemens"
Simatic Ipc Diagmonitor
Search vendor "Siemens" for product "Simatic Ipc Diagmonitor"
--
Safe
Siemens
Search vendor "Siemens"
Siplus Et 200sp Cp 1542sp-1 Irc Tx Rail Firmware
Search vendor "Siemens" for product "Siplus Et 200sp Cp 1542sp-1 Irc Tx Rail Firmware"
*-
Affected
in Siemens
Search vendor "Siemens"
Siplus Et 200sp Cp 1542sp-1 Irc Tx Rail
Search vendor "Siemens" for product "Siplus Et 200sp Cp 1542sp-1 Irc Tx Rail"
--
Safe
Siemens
Search vendor "Siemens"
Siplus Et 200sp Cp 1543sp-1 Isec Firmware
Search vendor "Siemens" for product "Siplus Et 200sp Cp 1543sp-1 Isec Firmware"
*-
Affected
in Siemens
Search vendor "Siemens"
Siplus Et 200sp Cp 1543sp-1 Isec
Search vendor "Siemens" for product "Siplus Et 200sp Cp 1543sp-1 Isec"
--
Safe
Siemens
Search vendor "Siemens"
Siplus Et 200sp Cp 1543sp-1 Isec Tx Rail Firmware
Search vendor "Siemens" for product "Siplus Et 200sp Cp 1543sp-1 Isec Tx Rail Firmware"
*-
Affected
in Siemens
Search vendor "Siemens"
Siplus Et 200sp Cp 1543sp-1 Isec Tx Rail
Search vendor "Siemens" for product "Siplus Et 200sp Cp 1543sp-1 Isec Tx Rail"
--
Safe
Siemens
Search vendor "Siemens"
Siplus Net Cp 1242-7 V2 Firmware
Search vendor "Siemens" for product "Siplus Net Cp 1242-7 V2 Firmware"
*-
Affected
in Siemens
Search vendor "Siemens"
Siplus Net Cp 1242-7 V2
Search vendor "Siemens" for product "Siplus Net Cp 1242-7 V2"
--
Safe
Siemens
Search vendor "Siemens"
Siplus Net Cp 443-1 Firmware
Search vendor "Siemens" for product "Siplus Net Cp 443-1 Firmware"
< 3.3
Search vendor "Siemens" for product "Siplus Net Cp 443-1 Firmware" and version " < 3.3"
-
Affected
in Siemens
Search vendor "Siemens"
Siplus Net Cp 443-1
Search vendor "Siemens" for product "Siplus Net Cp 443-1"
--
Safe
Siemens
Search vendor "Siemens"
Siplus Net Cp 443-1 Advanced Firmware
Search vendor "Siemens" for product "Siplus Net Cp 443-1 Advanced Firmware"
< 3.3
Search vendor "Siemens" for product "Siplus Net Cp 443-1 Advanced Firmware" and version " < 3.3"
-
Affected
in Siemens
Search vendor "Siemens"
Siplus Net Cp 443-1 Advanced
Search vendor "Siemens" for product "Siplus Net Cp 443-1 Advanced"
--
Safe
Siemens
Search vendor "Siemens"
Siplus S7-1200 Cp 1243-1 Firmware
Search vendor "Siemens" for product "Siplus S7-1200 Cp 1243-1 Firmware"
*-
Affected
in Siemens
Search vendor "Siemens"
Siplus S7-1200 Cp 1243-1
Search vendor "Siemens" for product "Siplus S7-1200 Cp 1243-1"
--
Safe
Siemens
Search vendor "Siemens"
Siplus S7-1200 Cp 1243-1 Rail Firmware
Search vendor "Siemens" for product "Siplus S7-1200 Cp 1243-1 Rail Firmware"
*-
Affected
in Siemens
Search vendor "Siemens"
Siplus S7-1200 Cp 1243-1 Rail
Search vendor "Siemens" for product "Siplus S7-1200 Cp 1243-1 Rail"
--
Safe
Siemens
Search vendor "Siemens"
Siplus Tim 1531 Irc Firmware
Search vendor "Siemens" for product "Siplus Tim 1531 Irc Firmware"
< 2.3.6
Search vendor "Siemens" for product "Siplus Tim 1531 Irc Firmware" and version " < 2.3.6"
-
Affected
in Siemens
Search vendor "Siemens"
Siplus Tim 1531 Irc
Search vendor "Siemens" for product "Siplus Tim 1531 Irc"
--
Safe
Siemens
Search vendor "Siemens"
Tim 1531 Irc Firmware
Search vendor "Siemens" for product "Tim 1531 Irc Firmware"
< 2.3.6
Search vendor "Siemens" for product "Tim 1531 Irc Firmware" and version " < 2.3.6"
-
Affected
in Siemens
Search vendor "Siemens"
Tim 1531 Irc
Search vendor "Siemens" for product "Tim 1531 Irc"
--
Safe