Inadequate Command Processing in SCALANCE Network Devices by Siemens
CVE-2022-46144
6.5MEDIUM
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 13 December 2022
Summary
A vulnerability exists in several SCALANCE network devices from Siemens where improper processing of CLI commands occurs after an SSH connection is abruptly terminated by the user. This flaw allows an authenticated attacker to disrupt the command line interface, which may lead to a denial of service condition, making the interface non-responsive. Affected versions of devices include various models within the SC622, SC626, SC632, SC636, SC642, SC646, and WAM series.
Affected Version(s)
SCALANCE SC622-2C 0
SCALANCE SC622-2C V2.3
SCALANCE SC626-2C 0
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved