CVE-2022-34821 | Siemens SIMATIC CP 1242-7 V2 OpenVPN Configuration code injection (ssa-517377 / EUVD-2022-37727)
A vulnerability categorized as critical has been discovered in Siemens SIMATIC CP 1242-7 V2, SIMATIC CP 1243-1, SIMATIC CP 1243-7 LTE EU, SIMATIC CP 1243-7 LTE US, SIMATIC CP 1243-8 IRC, SIMATIC CP 1542SP-1 IRC, SIMATIC CP 1543-1, SIMATIC CP 1543SP-1, SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL, SIPLUS ET 200SP CP 1543SP-1 ISEC, SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL, SIPLUS NET CP 1242-7 V2, SIPLUS NET CP 1543-1, SIPLUS S7-1200 CP 1243-1 and SIPLUS S7-1200 CP 1243-1 RAIL. Affected by this vulnerability is an unknown functionality of the component OpenVPN Configuration Handler. The manipulation results in code injection.
This vulnerability is known as CVE-2022-34821. Access to the local network is required for this attack. No exploit is available.
It is advisable to upgrade the affected component.