← Back

CVE-2022-25752

nvd nist
Published: Apr 12, 2022Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A vulnerability has been identified in SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 EEC (24V), SCALANCE X302-7 EEC (24V, coated), SCALANCE X302-7 EEC (2x 230V), SCALANCE X302-7 EEC (2x 230V, coated), SCALANCE X302-7 EEC (2x 24V), SCALANCE X302-7 EEC (2x 24V, coated), SCALANCE X304-2FE, SCALANCE X306-1LD FE, SCALANCE X307-2 EEC (230V), SCALANCE X307-2 EEC (230V, coated), SCALANCE X307-2 EEC (24V), SCALANCE X307-2 EEC (24V, coated), SCALANCE X307-2 EEC (2x 230V), SCALANCE X307-2 EEC (2x 230V, coated), SCALANCE X307-2 EEC (2x 24V), SCALANCE X307-2 EEC (2x 24V, coated), SCALANCE X307-3, SCALANCE X307-3, SCALANCE X307-3LD, SCALANCE X307-3LD, SCALANCE X308-2, SCALANCE X308-2, SCALANCE X308-2LD, SCALANCE X308-2LD, SCALANCE X308-2LH, SCALANCE X308-2LH, SCALANCE X308-2LH+, SCALANCE X308-2LH+, SCALANCE X308-2M, SCALANCE X308-2M, SCALANCE X308-2M PoE, SCALANCE X308-2M PoE, SCALANCE X308-2M TS, SCALANCE X308-2M TS, SCALANCE X310, SCALANCE X310, SCALANCE X310FE, SCALANCE X310FE, SCALANCE X320-1 FE, SCALANCE X320-1-2LD FE, SCALANCE X408-2, SCALANCE XR324-12M (230V, ports on front), SCALANCE XR324-12M (230V, ports on front), SCALANCE XR324-12M (230V, ports on rear), SCALANCE XR324-12M (230V, ports on rear), SCALANCE XR324-12M (24V, ports on front), SCALANCE XR324-12M (24V, ports on front), SCALANCE XR324-12M (24V, ports on rear), SCALANCE XR324-12M (24V, ports on rear), SCALANCE XR324-12M TS (24V), SCALANCE XR324-12M TS (24V), SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on front), SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on front), SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on rear), SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on rear), SCALANCE XR324-4M EEC (24V, ports on front), SCALANCE XR324-4M EEC (24V, ports on front), SCALANCE XR324-4M EEC (24V, ports on rear), SCALANCE XR324-4M EEC (24V, ports on rear), SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on front), SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on front), SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on rear), SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on rear), SCALANCE XR324-4M EEC (2x 24V, ports on front), SCALANCE XR324-4M EEC (2x 24V, ports on front), SCALANCE XR324-4M EEC (2x 24V, ports on rear), SCALANCE XR324-4M EEC (2x 24V, ports on rear), SCALANCE XR324-4M PoE (230V, ports on front), SCALANCE XR324-4M PoE (230V, ports on rear), SCALANCE XR324-4M PoE (24V, ports on front), SCALANCE XR324-4M PoE (24V, ports on rear), SCALANCE XR324-4M PoE TS (24V, ports on front), SIPLUS NET SCALANCE X308-2. The webserver of affected devices calculates session ids and nonces in an insecure manner. This could allow an unauthenticated remote attacker to brute-force session ids and hijack existing sessions.

Affected (24)

23 products
Scalance X302 7eec Firmware
Scalance X304 2fe Firmware
Scalance X306 1ldfe Firmware
Scalance X307 2eec Firmware
Scalance X307 3 Firmware
Scalance X307 3ld Firmware
Scalance X308 2 Firmware
Scalance X308 2ld Firmware
Scalance X308 2lh+ Firmware
Scalance X308 2m Firmware
Scalance X308 2m Poe Firmware
Scalance X308 2m Ts Firmware
Scalance X310 Firmware
Scalance X310fe Firmware
Scalance X320 1fe Firmware
Scalance X320 1 2ldfe Firmware
Scalance X408 2 Firmware
Scalance Xr324 4m Eec Firmware
Scalance Xr324 4m Poe Firmware
Scalance Xr324 4m Poe Ts Firmware
Scalance Xr324 12m Firmware
Scalance Xr324 12m Ts Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 4.1.4
Running on/withPlatform Versions
Siemens
Scalance X302 7eec
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 4.1.4
Running on/withPlatform Versions
Siemens
Scalance X304 2fe
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 4.1.4
Running on/withPlatform Versions
Siemens
Scalance X306 1ldfe
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 4.1.4
Running on/withPlatform Versions
Siemens
Scalance X307 2eec
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 4.1.4
Running on/withPlatform Versions
Siemens
Scalance X307 3
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 4.1.4
Running on/withPlatform Versions
Siemens
Scalance X307 3ld
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 4.1.4
Running on/withPlatform Versions
Siemens
Scalance X308 2
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 4.1.4
Running on/withPlatform Versions
Siemens
Scalance X308 2ld
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 4.1.4
Running on/withPlatform Versions
Siemens
Scalance X308 2lh
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 4.1.4
Running on/withPlatform Versions
Siemens
Scalance X308 2lh+
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 4.1.4
Running on/withPlatform Versions
Siemens
Scalance X308 2m
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Siemens
Scalance X308 2m Poe
All versions
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 4.1.4
Running on/withPlatform Versions
Siemens
Scalance X308 2m Ts
All versions
Configuration N
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 4.1.4
Running on/withPlatform Versions
Siemens
Scalance X310
All versions
Configuration O
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 4.1.4
Running on/withPlatform Versions
Siemens
Scalance X310fe
All versions
Configuration P
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 4.1.4
Running on/withPlatform Versions
Siemens
Scalance X320 1fe
All versions
Configuration Q
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 4.1.4
Running on/withPlatform Versions
Siemens
Scalance X320 1 2ldfe
All versions
Configuration R
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 4.1.4
Running on/withPlatform Versions
Siemens
Scalance X408 2
All versions
Configuration S
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 4.1.4
Running on/withPlatform Versions
Siemens
Scalance Xr324 4m Eec
All versions
Configuration T
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 4.1.4
Running on/withPlatform Versions
Siemens
Scalance Xr324 4m Poe
All versions
Configuration U
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 4.1.4
Running on/withPlatform Versions
Siemens
Scalance Xr324 4m Poe Ts
All versions
Configuration V
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 4.1.4
Running on/withPlatform Versions
Siemens
Scalance Xr324 12m
All versions
Configuration W
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 4.1.4
Running on/withPlatform Versions
Siemens
Scalance Xr324 12m Ts
All versions
Configuration X
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 4.1.4
Running on/withPlatform Versions
Siemens
Siplus Net Scalance X308 2
All versions

References (2)

Source: productcert@siemens.com
MitigationPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationPatchVendor Advisory

Timeline

No history available yet.