CVE-2022-25751
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
A vulnerability has been identified in SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 EEC (24V), SCALANCE X302-7 EEC (24V, coated), SCALANCE X302-7 EEC (2x 230V), SCALANCE X302-7 EEC (2x 230V, coated), SCALANCE X302-7 EEC (2x 24V), SCALANCE X302-7 EEC (2x 24V, coated), SCALANCE X304-2FE, SCALANCE X306-1LD FE, SCALANCE X307-2 EEC (230V), SCALANCE X307-2 EEC (230V, coated), SCALANCE X307-2 EEC (24V), SCALANCE X307-2 EEC (24V, coated), SCALANCE X307-2 EEC (2x 230V), SCALANCE X307-2 EEC (2x 230V, coated), SCALANCE X307-2 EEC (2x 24V), SCALANCE X307-2 EEC (2x 24V, coated), SCALANCE X307-3, SCALANCE X307-3, SCALANCE X307-3LD, SCALANCE X307-3LD, SCALANCE X308-2, SCALANCE X308-2, SCALANCE X308-2LD, SCALANCE X308-2LD, SCALANCE X308-2LH, SCALANCE X308-2LH, SCALANCE X308-2LH+, SCALANCE X308-2LH+, SCALANCE X308-2M, SCALANCE X308-2M, SCALANCE X308-2M PoE, SCALANCE X308-2M PoE, SCALANCE X308-2M TS, SCALANCE X308-2M TS, SCALANCE X310, SCALANCE X310, SCALANCE X310FE, SCALANCE X310FE, SCALANCE X320-1 FE, SCALANCE X320-1-2LD FE, SCALANCE X408-2, SCALANCE XR324-12M (230V, ports on front), SCALANCE XR324-12M (230V, ports on front), SCALANCE XR324-12M (230V, ports on rear), SCALANCE XR324-12M (230V, ports on rear), SCALANCE XR324-12M (24V, ports on front), SCALANCE XR324-12M (24V, ports on front), SCALANCE XR324-12M (24V, ports on rear), SCALANCE XR324-12M (24V, ports on rear), SCALANCE XR324-12M TS (24V), SCALANCE XR324-12M TS (24V), SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on front), SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on front), SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on rear), SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on rear), SCALANCE XR324-4M EEC (24V, ports on front), SCALANCE XR324-4M EEC (24V, ports on front), SCALANCE XR324-4M EEC (24V, ports on rear), SCALANCE XR324-4M EEC (24V, ports on rear), SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on front), SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on front), SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on rear), SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on rear), SCALANCE XR324-4M EEC (2x 24V, ports on front), SCALANCE XR324-4M EEC (2x 24V, ports on front), SCALANCE XR324-4M EEC (2x 24V, ports on rear), SCALANCE XR324-4M EEC (2x 24V, ports on rear), SCALANCE XR324-4M PoE (230V, ports on front), SCALANCE XR324-4M PoE (230V, ports on rear), SCALANCE XR324-4M PoE (24V, ports on front), SCALANCE XR324-4M PoE (24V, ports on rear), SCALANCE XR324-4M PoE TS (24V, ports on front), SIPLUS NET SCALANCE X308-2. Affected devices do not properly validate the HTTP headers of incoming requests. This could allow an unauthenticated remote attacker to crash affected devices.
Affected (24)
Products: Siemens: Scalance X302 7eec Firmware, Scalance X304 2fe Firmware, Scalance X306 1ldfe Firmware, Scalance X307 2eec Firmware, Scalance X307 3 Firmware, Scalance X307 3ld Firmware, Scalance X308 2 Firmware, Scalance X308 2ld Firmware, Scalance X308 2lh+ Firmware, Scalance X308 2m Firmware, Scalance X308 2m Poe Firmware, Scalance X308 2m Ts Firmware, Scalance X310 Firmware, Scalance X310fe Firmware, Scalance X320 1fe Firmware, Scalance X320 1 2ldfe Firmware, Scalance X408 2 Firmware, Scalance Xr324 4m Eec Firmware, Scalance Xr324 4m Poe Firmware, Scalance Xr324 4m Poe Ts Firmware, Scalance Xr324 12m Firmware, Scalance Xr324 12m Ts Firmware, Siplus Net Scalance X308 2 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.1.4 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance X302 7eec | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.1.4 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance X304 2fe | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.1.4 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance X306 1ldfe | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.1.4 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance X307 2eec | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.1.4 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance X307 3 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.1.4 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance X307 3ld | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.1.4 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance X308 2 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.1.4 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance X308 2ld | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.1.4 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance X308 2lh | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.1.4 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance X308 2lh+ | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.1.4 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance X308 2m | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance X308 2m Poe | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.1.4 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance X308 2m Ts | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.1.4 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance X310 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.1.4 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance X310fe | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.1.4 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance X320 1fe | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.1.4 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance X320 1 2ldfe | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.1.4 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance X408 2 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.1.4 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance Xr324 4m Eec | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.1.4 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance Xr324 4m Poe | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.1.4 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance Xr324 4m Poe Ts | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.1.4 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance Xr324 12m | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.1.4 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance Xr324 12m Ts | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.1.4 |
| Running on/with | Platform Versions |
|---|---|
Siemens Siplus Net Scalance X308 2 | All versions |
References (2)
Source: productcert@siemens.com
MitigationPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationPatchVendor Advisory
Timeline
No history available yet.