SSA-187092 PUBLISHED CVSS 9.800000190734863 CRITICAL

Several SCALANCE X-200 switches contain buffer overflow vulnerabilities in the web server. In the most severe case an attacker could potentially remotely execute code. Siemens is preparing updates and recommends specific countermeasures for products where updates are not, or not yet available.

Risk Scores

CVSS v3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C

Affected Products

VendorProductVersions
SCALANCE X204-2TS
SCALANCE X204-2FM
SCALANCE X212-2LD
SCALANCE X204 IRT
SCALANCE X208 (incl. SIPLUS NET variant)
SCALANCE X201-3P IRT
SCALANCE X204-2LD TS
SCALANCE X202-2 IRT
SCALANCE X204-2LD (incl. SIPLUS NET variant)
SCALANCE X212-2 (incl. SIPLUS NET variant)
SCALANCE X200-4P IRT
SCALANCE X208PRO
SCALANCE X206-1LD
SCALANCE X202-2P IRT (incl. SIPLUS NET variant)
SCALANCE X202-2P IRT PRO
SCALANCE X216
SCALANCE X204-2 (incl. SIPLUS NET variant)
SCALANCE X206-1
SCALANCE X201-3P IRT PRO
SCALANCE X204 IRT PRO

Timeline

References

Open in Interactive Console →