CVE-2022-38773

MEDIUM

Siemens SIMATIC S7-1500 and Drive Controller - Immutable Root of Trust in Hardware Missing

Title source: llm
STIX 2.1

Description

Affected devices do not contain an Immutable Root of Trust in Hardware. With this the integrity of the code executed on the device can not be validated during load-time. An attacker with physical access to the device could use this to replace the boot image of the device and execute arbitrary code.

Scores

CVSS v3 4.6
EPSS 0.0016
EPSS Percentile 36.8%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1326
Status published
Products (50)
siemens/simatic_drive_controller_cpu_1504d_tf_firmware
siemens/simatic_drive_controller_cpu_1507d_tf_firmware
siemens/simatic_s7-1500_cpu_1510sp-1_pn_firmware
siemens/simatic_s7-1500_cpu_1510sp_f-1_pn_firmware
siemens/simatic_s7-1500_cpu_1511-1_pn_firmware
siemens/simatic_s7-1500_cpu_1511c-1_pn_firmware
siemens/simatic_s7-1500_cpu_1511f-1_pn_firmware
siemens/simatic_s7-1500_cpu_1511t-1_pn_firmware
siemens/simatic_s7-1500_cpu_1511tf-1_pn_firmware
siemens/simatic_s7-1500_cpu_1512c-1_pn_firmware
... and 40 more
Published Jan 10, 2023
Tracked Since Feb 18, 2026