CVE-2022-30938 describes a memory corruption vulnerability in various Siemens EN100 Ethernet module variants (DNP3 IP, IEC 104, IEC 61850 < V4.40, Modbus TCP, PROFINET IO). An unauthenticated attacker can trigger a denial-of-service condition by sending specially crafted HTTP packets to the /txtrace endpoint. This vulnerability has a CVSS score of 7.5 (High) due to its network attack vector and low attack complexity, leading to a high impact on availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, though it has received some media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:siemens:en100_ethernet_module_dnp3_ip_firmware:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:siemens:en100_ethernet_module_iec_104_firmware:*:*:*:*:*:*:*:* | ||
< 4.40CPE matchmatch criteria | cpe:2.3:o:siemens:en100_ethernet_module_iec_61850_firmware:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:siemens:en100_ethernet_module_modbus_tcp_firmware:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:siemens:en100_ethernet_module_profinet_io_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.