VDB
ICSA-23-080-07
ICSA-23-080-07
PUBLISHED
CVSS 8.100000381469727 HIGH
Multiple vulnerabilities affecting various third-party components of SCALANCE W-700 IEEE 802.11ax devices before V2.0 could allow an attacker to cause a denial of service condition, disclose sensitive data or violate the system integrity. Siemens has released an update for SCALANCE W-700 IEEE 802.11ax and recommends to update to the latest version.
Risk Scores
CVSS 3.1
8.100000381469727
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SCALANCE WAM766-1 EEC (US) (6GK5766-1GE00-7TB0) | ||
| SCALANCE WUM766-1 (EU) (6GK5766-1GE00-3DA0) | ||
| SCALANCE WAM766-1 EEC (EU) (6GK5766-1GE00-7TA0) | ||
| SCALANCE WAM763-1 (6GK5763-1AL00-7DA0) | ||
| SCALANCE WUM766-1 (US) (6GK5766-1GE00-3DB0) | ||
| SCALANCE WUM763-1 (6GK5763-1AL00-3AA0) | ||
| SCALANCE WAM766-1 (EU) (6GK5766-1GE00-7DA0) | ||
| SCALANCE WAM766-1 (US) (6GK5766-1GE00-7DB0) | ||
| SCALANCE WUM763-1 (6GK5763-1AL00-3DA0) |
Exploit Intelligence
- https://cert-portal.siemens.com/productcert/csaf/ssa-565386.json (circl)
- https://cert-portal.siemens.com/productcert/txt/ssa-565386.txt (circl)
- https://cert-portal.siemens.com/productcert/pdf/ssa-565386.pdf (circl)
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2023/icsa-23-080-07.json (circl)
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-080-07 (circl)
- https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01 (circl)
- https://www.cisa.gov/resources-tools/resources/ics-recommended-practices (circl)
- https://www.cisa.gov/topics/industrial-control-systems (circl)
- https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf (circl)
- https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf (circl)
…and 2 more exploits
Timeline
- Mar 14, 2023 CVE Published
References
- https://cert-portal.siemens.com/productcert/csaf/ssa-565386.json advisory
- https://cert-portal.siemens.com/productcert/txt/ssa-565386.txt advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-565386.pdf advisory
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2023/icsa-23-080-07.json advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-080-07 advisory
- https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01 url
- https://www.cisa.gov/resources-tools/resources/ics-recommended-practices url
- https://www.cisa.gov/topics/industrial-control-systems url
- https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf url
- https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf url
- https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B url
- https://support.industry.siemens.com/cs/ww/en/view/109815650/ fix