Headline
CVE-2022-40227
A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V17 Update 4), SIMATIC HMI KTP Mobile Panels (All versions < V17 Update 4), SIMATIC HMI KTP1200 Basic (All versions < V17 Update 5), SIMATIC HMI KTP400 Basic (All versions < V17 Update 5), SIMATIC HMI KTP700 Basic (All versions < V17 Update 5), SIMATIC HMI KTP900 Basic (All versions < V17 Update 5), SIPLUS HMI KTP1200 BASIC (All versions < V17 Update 5), SIPLUS HMI KTP400 BASIC (All versions < V17 Update 5), SIPLUS HMI KTP700 BASIC (All versions < V17 Update 5), SIPLUS HMI KTP900 BASIC (All versions < V17 Update 5). Affected devices do not properly validate input sent to certain services over TCP. This could allow an unauthenticated remote attacker to cause a permanent denial of service condition (requiring a device reboot) by sending specially crafted TCP packets.
%PDF-1.5 %���� 85 0 obj << /Length 2377 /Filter /FlateDecode >> stream x�͛[w�H���)�(=���%g_��d��’^���gf0�6g0x��O��V߰Y�l?$��T�*U���B��M��OG��G��I2�ʤ�(����2 ���(�=��|Zd�t�ˇ�y�!"�?�Pw�0.f0�p��2��^9�|>-��ɇ���g��}��}D�!��’R�$û������}I0bF’��Ȼ��g�=IzG�>�!���bӆ��DX�&��#��Ҥˏ� a�p�� �C�z�ӜR�n3 ""t��Z^�j��ۘ�1&��’#"�j��t<�l�N1AJ�����P5�S,�[�^J����ƴ���Ϯk’�-S���"i�����q0f�z�䶑p�0�5!(��l��P [%A3��X7֘Pku�=�8]L��|p5�X l���xJx�8�d�U Q��i��c���1��8�4��[��V��#�d�~�1�����|��p���f�A����3��n�#xcYcB�E�ϳ�5�Kmުf��@�����T7z. �d ;�vL�I�X�}���\HP��]a,�X��r2��l���A���܄�RL) �C���-d�S��_E�Ϲ����"乳�?�d1���p��L�4�pu8�M������z�����z?(�0�gs뀒"UH�N�6R$�’v�u8���6�IXB/cB/\��u/2���ً��b�� C�\�h�;�⌚�!����a6�0!|��]��[���m�P��`��#�6�a���H�Cn�?��a3��n������l1Ó�,��L�gY���_�?;���r�OE���͚0���g������