Buffer Overflow Vulnerability in Siemens SCALANCE X Series Products
CVE-2022-25753

8.8HIGH

Summary

A buffer overflow vulnerability has been discovered in the Command Line Interface (CLI) of multiple Siemens SCALANCE X products. This vulnerability arises from improper handling of input arguments, specifically IP addresses, enabling an authenticated remote attacker to potentially execute arbitrary code on affected devices. This issue impacts a wide range of models within the SCALANCE X series, creating significant risks for environments utilizing these devices.

Affected Version(s)

SCALANCE X302-7 EEC (230V, coated) All versions < V4.1.4

SCALANCE X302-7 EEC (230V) All versions < V4.1.4

SCALANCE X302-7 EEC (24V, coated) All versions < V4.1.4

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.