CVE-2022-45147
Published: Jul 9, 2024
Modified: Aug 27, 2025
CVSS v3.1
7.8
Description
A vulnerability has been identified in SIMATIC PCS neo V4.0 (All versions), SIMATIC STEP 7 V16 (All versions), SIMATIC STEP 7 V17 (All versions), SIMATIC STEP 7 V18 (All versions < V18 Update 2). Affected applications do not properly restrict the .NET BinaryFormatter when deserializing user-controllable input. This could allow an attacker to cause a type confusion and execute arbitrary code within the affected application. This is the same issue that exists for .NET BinaryFormatter https://docs.microsoft.com/en-us/visualstudio/code-quality/ca2300.
| Vendor | Product | Versions |
|---|---|---|
Siemens | SIMATIC PCS neo V4.0 | affected 0 - < * |
Siemens | SIMATIC STEP 7 V16 | affected 0 - < * |
Siemens | SIMATIC STEP 7 V17 | affected 0 - < * |
Siemens | SIMATIC STEP 7 V18 | affected 0 - < V18 Update 2 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now