VDB
SSA-089022
SSA-089022
PUBLISHED
CVSS 7.800000190734863 HIGH
SINEC OS before V3.3 contains third-party components with multiple vulnerabilities. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3) | ||
| SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3) | ||
| SCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3) | ||
| SCALANCE XCM328 (6GK5328-4TS01-2AC2) | ||
| SCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3) | ||
| SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family | ||
| SCALANCE XCM324 (6GK5324-8TS01-2AC2) | ||
| SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3) | ||
| SCALANCE XCH328 (6GK5328-4TS01-2EC2) | ||
| SCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3) | ||
| SCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3) | ||
| SCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3) | ||
| SCALANCE XCM332 (6GK5332-0GA01-2AC2) | ||
| RUGGEDCOM RST2428P (6GK6242-6PA00) | ||
| SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3) | ||
| SCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3) |
Exploit Intelligence
- This project simulates a real-world attack-and-defend scenario across two virtual machines. You will exploit a critical pre-authentication RCE vulnerability (CVE-2025-32433) in an Erlang/OTP SSH server, crack extracted password hashes, and then harden the victim machine with firewall rules and patching. (github-poc-repo)
- This project simulates a real-world attack-and-defend scenario across two virtual machines. You will exploit a critical pre-authentication RCE vulnerability (CVE-2025-32433) in an Erlang/OTP SSH server, crack extracted password hashes, and then harden the victim machine with firewall rules and patching. (github-poc-repo)
- This project simulates a real-world attack-and-defend scenario across two virtual machines. You will exploit a critical pre-authentication RCE vulnerability (CVE-2025-32433) in an Erlang/OTP SSH server, crack extracted password hashes, and then harden the victim machine with firewall rules and patching. (github-poc)
- This project simulates a real-world attack-and-defend scenario across two virtual machines. You will exploit a critical pre-authentication RCE vulnerability (CVE-2025-32433) in an Erlang/OTP SSH server, crack extracted password hashes, and then harden the victim machine with firewall rules and patching. (github-poc)
- Based on the original version:https://github.com/vulhub/vulhub/blob/master/erlang/CVE-2025-32433/exploit.py Replace Unicode checkmark with ASCII character for Windows compatibility (github-poc-repo)
- Based on the original version:https://github.com/vulhub/vulhub/blob/master/erlang/CVE-2025-32433/exploit.py Replace Unicode checkmark with ASCII character for Windows compatibility (github-poc-repo)
- Based on the original version:https://github.com/vulhub/vulhub/blob/master/erlang/CVE-2025-32433/exploit.py Replace Unicode checkmark with ASCII character for Windows compatibility (github-poc)
- Based on the original version:https://github.com/vulhub/vulhub/blob/master/erlang/CVE-2025-32433/exploit.py Replace Unicode checkmark with ASCII character for Windows compatibility (github-poc)
- CVE-2025-32433 Erlang/OTP SSH RCE Exploit SSH远程代码执行漏洞EXP (github-poc-repo)
- CVE-2025-32433 Erlang/OTP SSH RCE Exploit SSH远程代码执行漏洞EXP (github-poc-repo)
…and 201 more exploits
Timeline
- Jan 28, 2026 CVE Published
- Feb 24, 2026 CVE Updated