VDB

CVE-2020-28395

CVE-2020-28395 PUBLISHED CVSS 4.300000190734863 MEDIUM

A vulnerability has been identified in SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.0). Devices do not create a new unique private key after factory reset. An attacker could leverage this situation to a man-in-the-middle situation and decrypt previously captured traffic.

EPSS 0.16% · 36.6th percentile

Risk Scores

CVSS v2.0
4.300000190734863
EPSS Score
0.16%
36.6th percentile

Affected Products

VendorProductVersions
siemensscalance_xr324-4m_eec_firmware0
SiemensSCALANCE X-200RNA switch familyAll versions < V3.2.7
siemensscalance_xr324-4m_poe_ts_firmware0
siemensscalance_xr324-12m_firmware0
siemensscalance_xr324wg_firmware0
siemensscalance_xr324-12m_ts_firmware0
siemensscalance_xr328-4c_wg_firmware0
siemensscalance_xr324-4m_poe_firmware0
siemensscalance_xr326-2c_poe_wg_firmware0
SiemensSCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants)*

Timeline

  • Jan 12, 2021 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 22, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 25, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 27, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Jul 2, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›