Vulnerability Details CVE-2022-36360
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Affected devices load firmware updates without checking the authenticity. Furthermore the integrity of the unencrypted firmware is only verified by a non-cryptographic method. This could allow an attacker to manipulate a firmware update and flash it to the device.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 31.5%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2022-36360
-
cpe:2.3:h:siemens:logo!8_bm:-
-
cpe:2.3:h:siemens:logo!8_bm_fs-05:-
-
cpe:2.3:o:siemens:logo!8_bm_fs-05_firmware:-
-
cpe:2.3:o:siemens:logo!8_bm_fs-05_firmware:1.81.1
-
cpe:2.3:o:siemens:logo!_8_bm_firmware:-
-
cpe:2.3:o:siemens:logo!_8_bm_firmware:1.81.01
-
cpe:2.3:o:siemens:logo!_8_bm_firmware:1.81.03
-
cpe:2.3:o:siemens:logo!_8_bm_firmware:1.81.04
-
cpe:2.3:o:siemens:logo!_8_bm_firmware:1.82.01
-
cpe:2.3:o:siemens:logo!_8_bm_firmware:1.82.02
-
cpe:2.3:o:siemens:logo!_8_bm_firmware:1.82.03
-
cpe:2.3:o:siemens:logo!_8_bm_firmware:1.82.04