{
  "document": {
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "publisher": {
      "category": "vendor",
      "name": "Softing Industrial Automation GmbH",
      "namespace": "https://industrial.softing.com",
      "contact_details": "Softing PSIRT - contact us at psirt@softing.com"
    },
    "title": "Multiple denial of service vulnerabilities in FastCGI interface of Secure Integration Server",
    "tracking": {
      "current_release_date": "2023-11-29T09:27:33.207Z",
      "id": "SYT-2022-4",
      "initial_release_date": "2022-07-27T10:00:00.000Z",
      "revision_history": [
        {
          "date": "2022-07-27T10:00:00.000Z",
          "number": "1.0.0",
          "summary": "Initial version"
        },
        {
          "number": "2.0.0",
          "summary": "Fix for Secure Integration Server",
          "date": "2023-11-29T09:27:33.207Z"
        }
      ],
      "status": "final",
      "version": "2.0.0",
      "generator": {
        "date": "2023-11-29T09:27:33.207Z",
        "engine": {
          "version": ".2.2.15",
          "name": "Secvisogram"
        }
      }
    },
    "source_lang": "en-US",
    "aggregate_severity": {
      "text": "high"
    },
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "The information provided in this disclosure is provided \"as is\" without warranty of any kind.\nSofting disclaims all warranties, either express or implied, including the warranties of\nmerchantability and fitness for a particular purpose. In no event shall Softing or its suppliers be\nliable for any damages whatsoever including direct, indirect, incidental, consequential, loss of\nbusiness profits or special damages, even if Softing or its suppliers have been advised of the\npossibility of such damages.\nSome states do not allow the exclusion or limitation of liability for consequential or incidental\ndamages so the foregoing limitation may not apply.\n",
        "title": "Disclaimer"
      }
    ]
  },
  "vulnerabilities": [
    {
      "acknowledgments": [
        {
          "names": [
            "Pedro Ribeiro",
            "Radek Domanski"
          ],
          "organization": "Flashback Team working with Trend Micro Zero Day Initiative"
        }
      ],
      "scores": [
        {
          "products": [
            "CSAFPID-0001"
          ],
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "availabilityImpact": "HIGH"
          }
        }
      ],
      "product_status": {
        "known_affected": [
          "CSAFPID-0001"
        ],
        "fixed": [
          "CSAFPID-0002"
        ]
      },
      "notes": [
        {
          "category": "summary",
          "text": "A crafted HTTP packet with a large Content-Length header can create a denial of service condition."
        }
      ],
      "discovery_date": "2022-04-15T10:00:00.000Z",
      "remediations": [
        {
          "category": "workaround",
          "details": "Configure the Windows firewall to block network requests to IP port 9000",
          "product_ids": [
            "CSAFPID-0001"
          ]
        }
      ],
      "release_date": "2022-07-01T10:00:00.000Z",
      "cwe": {
        "id": "CWE-125",
        "name": "Out-of-bounds Read"
      },
      "ids": [
        {
          "system_name": "Softing isssue id",
          "text": "2022-1"
        },
        {
          "system_name": "Trend Micro Zero Day Initiative issue id",
          "text": "ZDI-CAN-17060"
        }
      ],
      "cve": "CVE-2022-1069"
    },
    {
      "product_status": {
        "known_affected": [
          "CSAFPID-0001"
        ],
        "fixed": [
          "CSAFPID-0002"
        ]
      },
      "notes": [
        {
          "category": "summary",
          "text": "A crafted HTTP packet with a missing HTTP URI can create a denial of service condition."
        }
      ],
      "acknowledgments": [
        {
          "names": [
            "Pedro Ribeiro",
            "Radek Domanski"
          ],
          "organization": "Flashback Team working with Trend Micro Zero Day Initiative"
        }
      ],
      "cwe": {
        "id": "CWE-476",
        "name": "NULL Pointer Dereference"
      },
      "discovery_date": "2022-04-15T10:00:00.000Z",
      "ids": [
        {
          "system_name": "Softing isssue id",
          "text": "2022-11"
        },
        {
          "system_name": "Trend Micro Zero Day Initiative issue id",
          "text": "ZDI-CAN-17057"
        }
      ],
      "remediations": [
        {
          "category": "workaround",
          "details": "Configure the Windows firewall to block network requests to IP port 9000",
          "product_ids": [
            "CSAFPID-0001"
          ]
        }
      ],
      "scores": [
        {
          "products": [
            "CSAFPID-0001"
          ],
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "availabilityImpact": "HIGH"
          }
        }
      ],
      "cve": "CVE-2022-2337"
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Pedro Ribeiro",
            "Pedro Ribeiro"
          ],
          "organization": "Flashback Team working with Trend Micro Zero Day Initiative"
        }
      ],
      "cwe": {
        "id": "CWE-191",
        "name": "Integer Underflow (Wrap or Wraparound)"
      },
      "discovery_date": "2022-04-15T10:00:00.000Z",
      "ids": [
        {
          "system_name": "Softing isssue id",
          "text": "2022-12"
        },
        {
          "system_name": "Trend Micro Zero Day Initiative issue id",
          "text": "ZDI-CAN-17058"
        }
      ],
      "notes": [
        {
          "category": "summary",
          "text": "A crafted HTTP packet with a -1 Content-Lenght header can create a denial-of-service condition. "
        }
      ],
      "product_status": {
        "known_affected": [
          "CSAFPID-0001"
        ],
        "fixed": [
          "CSAFPID-0002"
        ]
      },
      "remediations": [
        {
          "category": "workaround",
          "details": "Configure the Windows firewall to block network requests to IP port 9000",
          "product_ids": [
            "CSAFPID-0001"
          ]
        }
      ],
      "scores": [
        {
          "products": [
            "CSAFPID-0001"
          ],
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "availabilityImpact": "HIGH"
          }
        }
      ],
      "cve": "CVE-2022-2335"
    },
    {
      "scores": [
        {
          "products": [
            "CSAFPID-0001"
          ],
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "availabilityImpact": "HIGH"
          }
        }
      ],
      "acknowledgments": [
        {
          "names": [
            "Pedro Ribeiro",
            "Radek Domanski"
          ],
          "organization": "Flashback Team working with Trend Micro Zero Day Initiative"
        }
      ],
      "cwe": {
        "id": "CWE-476",
        "name": "NULL Pointer Dereference"
      },
      "product_status": {
        "known_affected": [
          "CSAFPID-0001"
        ],
        "fixed": [
          "CSAFPID-0002"
        ]
      },
      "notes": [
        {
          "category": "summary",
          "text": "A crafted HTTP packet without a Content-Type header can create a denial-of-service condition.\n"
        }
      ],
      "remediations": [
        {
          "category": "workaround",
          "details": "Configure the Windows firewall to block network requests to IP port 9000",
          "product_ids": [
            "CSAFPID-0001"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Softing isssue id",
          "text": "2022-13"
        },
        {
          "system_name": "Trend Micro Zero Day Initiative issue id",
          "text": "ZDI-CAN-17059"
        }
      ],
      "cve": "CVE-2022-2547"
    }
  ],
  "product_tree": {
    "branches": [
      {
        "category": "product_version_range",
        "name": "Softing Secure Integration Server <= V1.22",
        "product": {
          "name": "Softing Secure Integration Server <= V1.22",
          "product_id": "CSAFPID-0001"
        }
      },
      {
        "category": "product_version",
        "name": "Softing Secure Integration Server V1.30",
        "product": {
          "name": "Softing Secure Integration Server V1.30",
          "product_id": "CSAFPID-0002"
        }
      }
    ]
  }
}