Unvalidated URI Vulnerability in SCALANCE X200 and X201 Series by Siemens
CVE-2022-26649

9.6CRITICAL

What is CVE-2022-26649?

A vulnerability in Siemens SCALANCE devices allows incoming HTTP GET requests to bypass proper URI validation. This flaw can be exploited by unauthenticated remote attackers, potentially leading to the crashing of affected devices. The vulnerability affects several models across the SCALANCE X200, X201, and XF series, particularly those running versions prior to V5.5.2 and V5.2.6. It is recommended that users update to the latest software versions to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

SCALANCE X200-4P IRT All versions < V5.5.2

SCALANCE X201-3P IRT All versions < V5.5.2

SCALANCE X201-3P IRT PRO All versions < V5.5.2

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.