SSA-089022 PUBLISHED CVSS 7.800000190734863 HIGH

There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution.

Risk Scores

CVSS v3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
SiemensSCALANCE XCM324 (6GK5324-8TS01-2AC2)
SiemensSCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-3AR3)
SiemensSCALANCE XRM334 (24 V DC, 8xFO) (6GK5334-2TS01-2AR3)
SiemensSCALANCE XRM334 (230 V AC, 12xFO) (6GK5334-3TS01-3AR3)
SiemensSCALANCE XCM332 (6GK5332-0GA01-2AC2)
SiemensRUGGEDCOM RST2428P (6GK6242-6PA00)
SiemensSCALANCE XRH334 (24 V DC, 8xFO, CC) (6GK5334-2TS01-2ER3)
SiemensSCALANCE XCM328 (6GK5328-4TS01-2AC2)
SiemensSCALANCE XCH328 (6GK5328-4TS01-2EC2)
SiemensSCALANCE XRM334 (230 V AC, 8xFO) (6GK5334-2TS01-3AR3)
SiemensSCALANCE XRM334 (2x230 V AC, 12xFO) (6GK5334-3TS01-4AR3)
SiemensSCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-2AR3)
SiemensSCALANCE XRM334 (24 V DC, 12xFO) (6GK5334-3TS01-2AR3)
SiemensSCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+) (6GK5334-5TS01-4AR3)
SiemensSCALANCE XRM334 (2x230 V AC, 8xFO) (6GK5334-2TS01-4AR3)
SiemensSCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family

Timeline

References

Open in Interactive Console →