The vendor explicitly identifies these products as affected by this CVE.
- AI Model Deployer
- Data Flow Monitoring Industrial Edge Device User Interface (DFM IED UI)
- LiveTwin Industrial Edge app (6AV2170-0BL00-0AA0)
- SIMATIC PCS neo V4.1
- SIMATIC PCS neo V5.0
- SIMATIC WinCC Runtime Professional V17
- SIMATIC WinCC Runtime Professional V18
- SIMATIC WinCC Runtime Professional V19
- SIMATIC WinCC V7.4
- SIMATIC WinCC V7.5
- SIMATIC WinCC V8.0
- TIA Administrator
- Summary
- Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. A specially crafted Socket.IO packet can trigger an uncaught exception on the Socket.IO server, thus killing the Node.js process. This issue is fixed by commit `15af22fc22` which has been included in `socket.io@4.6.2` (released in May 2023). The fix was backported in the 2.x branch as well with commit `d30630ba10`. Users are advised to upgrade. Users unable to upgrade may attach a listener for the "error" event to catch these errors.
- Remediation
- Update to V0.0.6 or later version
