Vulnerability Details CVE-2022-27194
A vulnerability has been identified in SIMATIC PCS neo (Administration Console) (All versions < V3.1 SP1), SINETPLAN (All versions), TIA Portal (V15, V15.1, V16 and V17). The affected system cannot properly process specially crafted packets sent to port 8888/tcp. A remote attacker could exploit this vulnerability to cause a Denial-of-Service condition. The affected devices must be restarted manually.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 48.1%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 7.8
Products affected by CVE-2022-27194
-
cpe:2.3:a:siemens:simatic_pcs_neo:-
-
cpe:2.3:a:siemens:simatic_pcs_neo:3.0
-
cpe:2.3:a:siemens:simatic_pcs_neo:3.1
-
cpe:2.3:a:siemens:sinetplan:-
-
cpe:2.3:a:siemens:sinetplan:2.0
-
cpe:2.3:a:siemens:totally_integrated_automation_portal:15
-
cpe:2.3:a:siemens:totally_integrated_automation_portal:15.1
-
cpe:2.3:a:siemens:totally_integrated_automation_portal:16
-
cpe:2.3:a:siemens:totally_integrated_automation_portal:17