Unvalidated URI Vulnerability in SCALANCE X200 and X201 Series by Siemens
CVE-2022-26649
9.6CRITICAL
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 12 July 2022
What is CVE-2022-26649?
A vulnerability in Siemens SCALANCE devices allows incoming HTTP GET requests to bypass proper URI validation. This flaw can be exploited by unauthenticated remote attackers, potentially leading to the crashing of affected devices. The vulnerability affects several models across the SCALANCE X200, X201, and XF series, particularly those running versions prior to V5.5.2 and V5.2.6. It is recommended that users update to the latest software versions to mitigate this risk.
Affected Version(s)
SCALANCE X200-4P IRT All versions < V5.5.2
SCALANCE X201-3P IRT All versions < V5.5.2
SCALANCE X201-3P IRT PRO All versions < V5.5.2