Description

A vulnerability has been identified in SIMATIC PCS neo V4.0 (All versions), SIMATIC STEP 7 V16 (All versions), SIMATIC STEP 7 V17 (All versions), SIMATIC STEP 7 V18 (All versions < V18 Update 2). Affected applications do not properly restrict the .NET BinaryFormatter when deserializing user-controllable input. This could allow an attacker to cause a type confusion and execute arbitrary code within the affected application. This is the same issue that exists for .NET BinaryFormatter https://docs.microsoft.com/en-us/visualstudio/code-quality/ca2300.

INFO

Published Date :

2024-07-09T12:04:22.545Z

Last Modified :

2025-08-27T20:32:52.249Z

Source :

siemens
AFFECTED PRODUCTS

The following products are affected by CVE-2022-45147 vulnerability.

Vendors Products
Siemens
  • Simatic Pcs Neo
  • Simatic Step 7
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2022-45147.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact