CVE-2022-30937
—CVSS 3.1
7.5 high
EPSS
1%p67
Published
()
Modified
Description
A vulnerability has been identified in EN100 Ethernet module DNP3 IP variant (All versions), EN100 Ethernet module IEC 104 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.37), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module PROFINET IO variant (All versions). Affected applications contains a memory corruption vulnerability while parsing specially crafted HTTP packets to /txtrace endpoint. This could allow an attacker to crash the affected application leading to a denial of service condition.
- Vendors
- siemens
- Products
- en100 ethernet module dnp3 firmware, en100 ethernet module iec 104 firmware, en100 ethernet module iec 61850 firmware, en100 ethernet module modbus tcp firmware, en100 ethernet module profinet io firmware
- Weakness
- CWE-119, CWE-787
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.