Inadequate Command Processing in SCALANCE Network Devices by Siemens
CVE-2022-46144

6.5MEDIUM

Key Information:

Vendor
Siemens
Vendor
CVE Published:
13 December 2022

Summary

A vulnerability exists in several SCALANCE network devices from Siemens where improper processing of CLI commands occurs after an SSH connection is abruptly terminated by the user. This flaw allows an authenticated attacker to disrupt the command line interface, which may lead to a denial of service condition, making the interface non-responsive. Affected versions of devices include various models within the SC622, SC626, SC632, SC636, SC642, SC646, and WAM series.

Affected Version(s)

SCALANCE SC622-2C 0

SCALANCE SC622-2C V2.3

SCALANCE SC626-2C 0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.