Incorrect Authorization Vulnerability in SCALANCE WAB and WAM Series by Siemens
CVE-2025-24532

5.3MEDIUM

Key Information:

Vendor
Siemens
Vendor
CVE Published:
11 February 2025

Summary

A vulnerability exists in various SCALANCE products where devices with the 'user' role may be compromised due to incorrect authorization in SNMPv3 View configuration. This exposes the potential for malicious actors to alter the View Type of SNMPv3 Views, which can have severe security implications for affected network infrastructures. It is crucial for users of these products to implement the necessary updates and safeguards against unauthorized modifications.

Affected Version(s)

SCALANCE WAB762-1 0

SCALANCE WAM763-1 0

SCALANCE WAM763-1 (ME) 0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.