Inadequate Command Processing in SCALANCE Network Devices by Siemens
CVE-2022-46144

7.1HIGH

Key Information:

Vendor
Siemens
Vendor
CVE Published:
13 December 2022

Summary

A vulnerability exists in several SCALANCE network devices from Siemens where improper processing of CLI commands occurs after an SSH connection is abruptly terminated by the user. This flaw allows an authenticated attacker to disrupt the command line interface, which may lead to a denial of service condition, making the interface non-responsive. Affected versions of devices include various models within the SC622, SC626, SC632, SC636, SC642, SC646, and WAM series.

Affected Version(s)

SCALANCE SC622-2C 0

SCALANCE SC622-2C V2.3

SCALANCE SC626-2C 0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.