VDB

SSA-620338

SSA-620338 PUBLISHED CVSS 7.800000190734863 HIGH

The affected devices contain an improper null termination vulnerability while parsing a specific HTTP header. This could allow an attacker to execute code in the context of the current process or lead to denial of service condition.

Risk Scores

CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
SiemensCPCX26 Central Processing/Communication
SiemensPCCX26 Ax 1703 PE, Contr, Communication Element
SiemensETA5 Ethernet Int. 1x100TX IEC61850 Ed.2
SiemensETA4 Ethernet Interface IEC60870-5-104

Timeline

  • Jun 11, 2024 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›