Buffer Overflow Vulnerability in Siemens SCALANCE X Series Products
CVE-2022-25753
8.8HIGH
Key Information:
- Vendor
- Siemens
- Status
- Vendor
- CVE Published:
- 12 April 2022
Summary
A buffer overflow vulnerability has been discovered in the Command Line Interface (CLI) of multiple Siemens SCALANCE X products. This vulnerability arises from improper handling of input arguments, specifically IP addresses, enabling an authenticated remote attacker to potentially execute arbitrary code on affected devices. This issue impacts a wide range of models within the SCALANCE X series, creating significant risks for environments utilizing these devices.
Affected Version(s)
SCALANCE X302-7 EEC (230V, coated) All versions < V4.1.4
SCALANCE X302-7 EEC (230V) All versions < V4.1.4
SCALANCE X302-7 EEC (24V, coated) All versions < V4.1.4
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved