Unvalidated URI Vulnerability in SCALANCE X200 and X201 Series by Siemens
CVE-2022-26649
9.6CRITICAL
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 12 July 2022
Summary
A vulnerability in Siemens SCALANCE devices allows incoming HTTP GET requests to bypass proper URI validation. This flaw can be exploited by unauthenticated remote attackers, potentially leading to the crashing of affected devices. The vulnerability affects several models across the SCALANCE X200, X201, and XF series, particularly those running versions prior to V5.5.2 and V5.2.6. It is recommended that users update to the latest software versions to mitigate this risk.
Affected Version(s)
SCALANCE X200-4P IRT All versions < V5.5.2
SCALANCE X201-3P IRT All versions < V5.5.2
SCALANCE X201-3P IRT PRO All versions < V5.5.2
References
CVSS V3.1
Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved