Arbitrary Command Execution Vulnerability in Siemens SCALANCE SC-600
CVE-2019-10928

6.6MEDIUM

Key Information:

Vendor
Siemens Ag
Vendor
CVE Published:
13 August 2019

Summary

A vulnerability has been discovered in the Siemens SCALANCE SC-600 version 2.0, where an authenticated attacker with access to port 22/tcp and physical access to the device can execute arbitrary commands. This flaw does not necessitate user interaction, making it particularly dangerous, as it poses significant risks to the confidentiality, integrity, and availability of the device. Organizations using this product should take immediate action to protect against potential exploitation.

Affected Version(s)

SCALANCE SC-600 V2.0

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.