CVE-2022-38100

The CMS800 device fails while attempting to parse malformed network data sent by a threat actor. A threat actor with network access can remotely issue a specially formatted UDP request that will cause the entire device to crash and require a physical reboot. A UDP broadcast request could be sent that causes a mass denial-of-service attack on all CME8000 devices connected to the same network.
References
Link Resource
https://www.cisa.gov/uscert/ics/advisories/icsma-22-244-01 Mitigation Third Party Advisory
Configurations

Configuration 1


Information

Published : 2022-09-13 03:15

Updated : 2022-09-14 10:48


NVD link : CVE-2022-38100

Mitre link : CVE-2022-38100

Products Affected
No products.
CWE