Lucene search

K
nvd[email protected]NVD:CVE-2022-42784
HistoryDec 12, 2023 - 10:15 a.m.

CVE-2022-42784

2023-12-1210:15:09
CWE-1319
web.nvd.nist.gov
1
vulnerability
logo devices
electromagnetic fault
firmware manipulation
impersonation

CVSS3

6.8

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

17.0%

A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA1) (All versions >= V8.3), LOGO! 12/24RCEo (6ED1052-2MD08-0BA1) (All versions >= V8.3), LOGO! 230RCE (6ED1052-1FB08-0BA1) (All versions >= V8.3), LOGO! 230RCEo (6ED1052-2FB08-0BA1) (All versions >= V8.3), LOGO! 24CE (6ED1052-1CC08-0BA1) (All versions >= V8.3), LOGO! 24CEo (6ED1052-2CC08-0BA1) (All versions >= V8.3), LOGO! 24RCE (6ED1052-1HB08-0BA1) (All versions >= V8.3), LOGO! 24RCEo (6ED1052-2HB08-0BA1) (All versions >= V8.3), SIPLUS LOGO! 12/24RCE (6AG1052-1MD08-7BA1) (All versions >= V8.3), SIPLUS LOGO! 12/24RCEo (6AG1052-2MD08-7BA1) (All versions >= V8.3), SIPLUS LOGO! 230RCE (6AG1052-1FB08-7BA1) (All versions >= V8.3), SIPLUS LOGO! 230RCEo (6AG1052-2FB08-7BA1) (All versions >= V8.3), SIPLUS LOGO! 24CE (6AG1052-1CC08-7BA1) (All versions >= V8.3), SIPLUS LOGO! 24CEo (6AG1052-2CC08-7BA1) (All versions >= V8.3), SIPLUS LOGO! 24RCE (6AG1052-1HB08-7BA1) (All versions >= V8.3), SIPLUS LOGO! 24RCEo (6AG1052-2HB08-7BA1) (All versions >= V8.3). Affected devices are vulnerable to an electromagnetic fault injection. This could allow an attacker to dump and debug the firmware, including the manipulation of memory. Further actions could allow to inject public keys of custom created key pairs which are then signed by the product CA. The generation of a custom certificate allows communication with, and impersonation of, any device of the same version.

Affected configurations

Nvd
Node
siemens6ed1052-1md08-0ba1Match-
AND
siemens6ed1052-1md08-0ba1_firmwareRange8.3
Node
siemens6ed1052-2md08-0ba1Match-
AND
siemens6ed1052-2md08-0ba1_firmwareRange8.3
Node
siemens6ed1052-1cc08-0ba1Match-
AND
siemens6ed1052-1cc08-0ba1_firmwareRange8.3
Node
siemens6ed1052-2cc08-0ba1Match-
AND
siemens6ed1052-2cc08-0ba1_firmwareRange8.3
Node
siemens6ed1052-1hb08-0ba1_firmwareRange8.3
AND
siemens6ed1052-1hb08-0ba1Match-
Node
siemens6ed1052-2hb08-0ba1_firmwareRange8.3
AND
siemens6ed1052-2hb08-0ba1Match-
Node
siemens6ed1052-1fb08-0ba1_firmwareRange8.3
AND
siemens6ed1052-1fb08-0ba1Match-
Node
siemens6ed1052-2fb08-0ba1_firmwareRange8.3
AND
siemens6ed1052-2fb08-0ba1Match-
Node
siemens6ag1052-1md08-7ba1_firmwareRange8.3
AND
siemens6ag1052-1md08-7ba1Match-
Node
siemens6ag1052-2md08-7ba1_firmwareRange8.3
AND
siemens6ag1052-2md08-7ba1Match-
Node
siemens6ag1052-1cc08-7ba1_firmwareRange8.3
AND
siemens6ag1052-1cc08-7ba1Match-
Node
siemens6ag1052-2cc08-7ba1_firmwareRange8.3
AND
siemens6ag1052-2cc08-7ba1Match-
Node
siemens6ag1052-1hb08-7ba1_firmwareRange8.3
AND
siemens6ag1052-1hb08-7ba1Match-
Node
siemens6ag1052-2hb08-7ba1_firmwareRange8.3
AND
siemens6ag1052-2hb08-7ba1Match-
Node
siemens6ag1052-1fb08-7ba1_firmwareRange8.3
AND
siemens6ag1052-1fb08-7ba1Match-
Node
siemens6ag1052-2fb08-7ba1_firmwareRange8.3
AND
siemens6ag1052-2fb08-7ba1Match-
VendorProductVersionCPE
siemens6ed1052-1md08-0ba1-cpe:2.3:h:siemens:6ed1052-1md08-0ba1:-:*:*:*:*:*:*:*
siemens6ed1052-1md08-0ba1_firmware*cpe:2.3:o:siemens:6ed1052-1md08-0ba1_firmware:*:*:*:*:*:*:*:*
siemens6ed1052-2md08-0ba1-cpe:2.3:h:siemens:6ed1052-2md08-0ba1:-:*:*:*:*:*:*:*
siemens6ed1052-2md08-0ba1_firmware*cpe:2.3:o:siemens:6ed1052-2md08-0ba1_firmware:*:*:*:*:*:*:*:*
siemens6ed1052-1cc08-0ba1-cpe:2.3:h:siemens:6ed1052-1cc08-0ba1:-:*:*:*:*:*:*:*
siemens6ed1052-1cc08-0ba1_firmware*cpe:2.3:o:siemens:6ed1052-1cc08-0ba1_firmware:*:*:*:*:*:*:*:*
siemens6ed1052-2cc08-0ba1-cpe:2.3:h:siemens:6ed1052-2cc08-0ba1:-:*:*:*:*:*:*:*
siemens6ed1052-2cc08-0ba1_firmware*cpe:2.3:o:siemens:6ed1052-2cc08-0ba1_firmware:*:*:*:*:*:*:*:*
siemens6ed1052-1hb08-0ba1_firmware*cpe:2.3:o:siemens:6ed1052-1hb08-0ba1_firmware:*:*:*:*:*:*:*:*
siemens6ed1052-1hb08-0ba1-cpe:2.3:h:siemens:6ed1052-1hb08-0ba1:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 321

CVSS3

6.8

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

17.0%

Related for NVD:CVE-2022-42784