Inadequate Command Processing in SCALANCE Network Devices by Siemens
CVE-2022-46144
7.1HIGH
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 13 December 2022
Summary
A vulnerability exists in several SCALANCE network devices from Siemens where improper processing of CLI commands occurs after an SSH connection is abruptly terminated by the user. This flaw allows an authenticated attacker to disrupt the command line interface, which may lead to a denial of service condition, making the interface non-responsive. Affected versions of devices include various models within the SC622, SC626, SC632, SC636, SC642, SC646, and WAM series.
Affected Version(s)
SCALANCE SC622-2C 0
SCALANCE SC622-2C V2.3
SCALANCE SC626-2C 0
References
CVSS V4
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved