{"document":{"acknowledgments":[{"organization":"CERT@VDE","summary":"coordination","urls":["https://certvde.com"]}],"category":"csaf_security_advisory","csaf_version":"2.0","distribution":{"tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en-GB","notes":[{"category":"summary","text":"A critical vulnerability has been discovered in the utilized component EtherNet/IP Adapter Development Kit (EADK) by Pyramid Solutions, Inc.. For details refer to CVE(s).This vulnerability may allow an attacker to send a specially crafted packet that may result in a denial-of-service condition of the affected products.\nThe indicated firmware versions are only used on products of hardware version 01.xx.xx.","title":"Summary"},{"category":"description","text":"Attackers with network access to the EtherNet/IP network may send a specially crafted packet that may result in a denial-of-service condition of the affected products which will cause them to crash. Crashed products will reboot within some seconds.","title":"Impact"},{"category":"description","text":"Weidmueller strongly recommends applying the following external protective measures:\n\nRestrict network access to the EtherNet/IP network containing affected products.\nIf remote access is required, use secure methods such as virtual private networks (VPNs).","title":"Mitigation"}],"publisher":{"category":"vendor","contact_details":"psirt@weidmueller.com","name":"Weidmueller Interface GmbH & Co. KG","namespace":"https://www.weidmueller.com"},"references":[{"category":"self","summary":"VDE-2021-004: Weidmueller: EtherNet/IP Fieldbus Coupler out-of-bounds write - HTML","url":"https://certvde.com/en/advisories/VDE-2021-004/"},{"category":"self","summary":"VDE-2021-004: Weidmueller: EtherNet/IP Fieldbus Coupler out-of-bounds write - CSAF","url":"https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2022/vde-2021-004.json"},{"category":"external","summary":"Weidmueller PSIRT","url":"https://www.weidmueller.com/int/solutions/solutions/industrial_security/index.jsp"},{"category":"external","summary":"CERT@VDE Security Advisories for Weidmueller Interface GmbH & Co. KG","url":"https://certvde.com/en/advisories/vendor/weidmueller/"}],"title":"Weidmueller: EtherNet/IP Fieldbus Coupler out-of-bounds write","tracking":{"aliases":["VDE-2021-004"],"current_release_date":"2022-06-21T08:00:00.000Z","generator":{"date":"2025-05-05T09:26:35.205Z","engine":{"name":"Secvisogram","version":"2.5.24"}},"id":"VDE-2021-004","initial_release_date":"2022-06-21T08:00:00.000Z","revision_history":[{"date":"2022-06-21T08:00:00.000Z","number":"1","summary":"Initial revision."}],"status":"final","version":"1"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_name","name":"UR20-FBC-EIP","product":{"name":"UR20-FBC-EIP","product_id":"CSAFPID-11001","product_identification_helper":{"model_numbers":["1334920000"]}}}],"category":"product_family","name":"Hardware"},{"branches":[{"category":"product_version_range","name":"01.00.00<=01.08.00","product":{"name":"Firmware 01.00.00 <= 01.08.00","product_id":"CSAFPID-21001"}}],"category":"product_family","name":"Firmware"}],"category":"vendor","name":"Weidmueller"}],"relationships":[{"category":"installed_on","full_product_name":{"name":"Firmware 01.00.00 <= 01.08.00 installed on UR20-FBC-EIP","product_id":"CSAFPID-31001"},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11001"}]},"vulnerabilities":[{"cve":"CVE-2022-1737","cwe":{"id":"CWE-787","name":"Out-of-bounds Write"},"notes":[{"category":"description","text":"Pyramid Solutions' affected products, the Developer and DLL kits for EtherNet/IP Adapter and EtherNet/IP Scanner, are vulnerable to an out-of-bounds write, which may allow an unauthorized attacker to send a specially crafted packet that may result in a denial-of-service condition.","title":"Vulnerability Description"}],"product_status":{"known_affected":["CSAFPID-31001"]},"remediations":[{"category":"mitigation","details":"Weidmueller strongly recommends applying the following external protective measures:\n\nRestrict network access to the EtherNet/IP network containing affected products.\nIf remote access is required, use secure methods such as virtual private networks (VPNs).","product_ids":["CSAFPID-31001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","environmentalScore":7.5,"environmentalSeverity":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":7.5,"temporalSeverity":"HIGH","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["CSAFPID-31001"]}],"title":"CVE-2022-1737"}]}