SSA-280834 PUBLISHED CVSS 3.700000047683716 LOW

Affected devices improperly validate usernames during OpenVPN authentication. This could allow an attacker to get partial invalid usernames accepted by the server.

Risk Scores

CVSS v3.1
3.700000047683716
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C

Affected Products

VendorProductVersions
SiemensSCALANCE MUM856-1 (A1) (6GK5856-2EA10-3AA1)
SiemensSCALANCE M876-3 (6GK5876-3AA02-2BA2)
SiemensSCALANCE M874-2 (6GK5874-2AA00-2AA2)
SiemensSCALANCE SC-600 family
SiemensSCALANCE M816-1 ADSL-Router family
SiemensSCALANCE MUM853-1 (EU) (6GK5853-2EA00-2DA1)
SiemensSCALANCE M874-3 (6GK5874-3AA00-2AA2)
SiemensSCALANCE M804PB (6GK5804-0AP00-2AA2)
SiemensSCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2)
SiemensSCALANCE M874-3 3G-Router (CN) (6GK5874-3AA00-2FA2)
SiemensSCALANCE MUM853-1 (A1) (6GK5853-2EA10-2AA1)
SiemensSCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1)
SiemensSCALANCE MUB852-1 (A1) (6GK5852-1EA10-1AA1)
SiemensSCALANCE M812-1 ADSL-Router family
SiemensSCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2)
SiemensSCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2)
SiemensSCALANCE MUM853-1 (B1) (6GK5853-2EA10-2BA1)
SiemensSCALANCE S615 EEC LAN-Router (6GK5615-0AA01-2AA2)
SiemensSCALANCE MUM856-1 (EU) (6GK5856-2EA00-3DA1)
SiemensRUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2)

…and 7 more

Timeline

References

Open in Interactive Console →