Successful exploitation of this remotely exploitable vulnerability, which Siemens self-reported, could allow an attacker to cause a permanent denial-of-service condition by sending specially crafted TCP packets. This condition would then require a device reboot.
In the vulnerability, affected devices do not properly validate input sent to certain services over TCP. This could allow an unauthenticated remote attacker to cause a permanent denial-of-service condition by sending specially crafted TCP packets. This condition would then require a device reboot.
CVE-2022-40227 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 7.5.
The following versions of SIMATIC HMIs suffer from the issue:
- SIMATIC HMI Comfort Panels (incl. SIPLUS variants): All versions prior to V17 Update 4
- SIMATIC HMI KTP400 Basic (6AV2123-2DB03-0AX0): All versions prior to V17 Update 5
- SIMATIC HMI KTP700 Basic (6AV2123-2GB03-0AX0): All versions prior to V17 Update 5
- SIMATIC HMI KTP900 Basic (6AV2123-2JB03-0AX0): All versions prior to V17 Update 5
- SIMATIC HMI KTP1200 Basic (6AV2123-2MB03-0AX0): All versions prior to V17 Update 5
- SIMATIC HMI KTP Mobile Panels: All versions prior to V17 Update 4
- SIPLUS HMI KTP400 BASIC (6AG1123-2DB03-2AX0): All versions prior to V17 Update 5
- SIPLUS HMI KTP700 BASIC (6AG1123-2GB03-2AX0): All versions prior to V17 Update 5
- SIPLUS HMI KTP900 BASIC (6AG1123-2JB03-2AX0): All versions prior to V17 Update 5
- SIPLUS HMI KTP1200 BASIC (6AG1123-2MB03-2AX0): All versions prior to V17 Update 5
The product sees use in multiple industrial sectors, and on a global basis.
No known public exploits specifically target this vulnerability. However, an attacker with low skill level could leverage this low complexity vulnerability.
Siemens released updates for the affected products and recommends users to update to the latest versions:
- SIMATIC HMI Comfort Panels (incl. SIPLUS variants): Update to V17 Update 4 or laterÂ
- SIMATIC HMI KTP400 Basic (6AV2123-2DB03-0AX0): Update to V17 Update 5 or laterÂ
- SIMATIC HMI KTP700 Basic (6AV2123-2GB03-0AX0): Update to V17 Update 5 or laterÂ
- SIMATIC HMI KTP900 Basic (6AV2123-2JB03-0AX0): Update to V17 Update 5 or laterÂ
- SIMATIC HMI KTP1200 Basic (6AV2123-2MB03-0AX0): Update to V17 Update 5 or laterÂ
- SIMATIC HMI KTP Mobile Panels: Update to V17 Update 4 or laterÂ
- SIPLUS HMI KTP400 BASIC (6AG1123-2DB03-2AX0): Update to V17 Update 5 or laterÂ
- SIPLUS HMI KTP700 BASIC (6AG1123-2GB03-2AX0): Update to V17 Update 5 or laterÂ
- SIPLUS HMI KTP900 BASIC (6AG1123-2JB03-2AX0): Update to V17 Update 5 or laterÂ
- SIPLUS HMI KTP1200 BASIC (6AG1123-2MB03-2AX0): Update to V17 Update 5 or laterÂ
Siemens identified the following workarounds and mitigations users can implement to reduce exploitation risk: Restrict access to ports 5001/TCP and 5002/TCP to trusted IP addresses.
As a general security measure, Siemens recommends protecting network access to devices with appropriate mechanisms. To operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens’ operational guidelines for industrial security and following recommendations in the product manuals.
Additional information on industrial security by Siemens can be found on the Siemens industrial security webpage.
For more information, click on Siemens Security Advisory SSA-384224.

