Denial of Service in RUGGEDCOM and SCALANCE Products by Siemens
CVE-2022-31766

8.6HIGH

Key Information:

Summary

A vulnerability has been found in select RUGGEDCOM and SCALANCE devices, where enabling TCP Event service can lead to improper handling of malformed packets. This can lead to an unauthenticated remote attacker causing a denial of service, resulting in device reboot and potential impact on network resources. Users are encouraged to update to versions V7.1.2 or higher to mitigate this risk.

Affected Version(s)

RUGGEDCOM RM1224 LTE(4G) EU All versions < V7.1.2

RUGGEDCOM RM1224 LTE(4G) NAM All versions < V7.1.2

SCALANCE M804PB All versions < V7.1.2

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.