Vulnerability Name: | CVE-2021-25669 (CCN-199902) |
Assigned: | 2021-04-13 |
Published: | 2021-04-13 |
Updated: | 2022-05-13 |
Summary: | A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < 5.5.1), SCALANCE X201-3P IRT (All versions < 5.5.1), SCALANCE X201-3P IRT PRO (All versions < 5.5.1), SCALANCE X202-2 IRT (All versions < 5.5.1), SCALANCE X202-2P IRT (incl. SIPLUS NET variant) (All versions < 5.5.1), SCALANCE X202-2P IRT PRO (All versions < 5.5.1), SCALANCE X204 IRT (All versions < 5.5.1), SCALANCE X204 IRT PRO (All versions < 5.5.1), SCALANCE X204-2 (incl. SIPLUS NET variant) (All versions < V5.2.5), SCALANCE X204-2FM (All versions < V5.2.5), SCALANCE X204-2LD (incl. SIPLUS NET variant) (All versions < V5.2.5), SCALANCE X204-2LD TS (All versions < V5.2.5), SCALANCE X204-2TS (All versions < V5.2.5), SCALANCE X206-1 (All versions < V5.2.5), SCALANCE X206-1LD (All versions < V5.2.5), SCALANCE X208 (incl. SIPLUS NET variant) (All versions < V5.2.5), SCALANCE X208PRO (All versions < V5.2.5), SCALANCE X212-2 (incl. SIPLUS NET variant) (All versions < V5.2.5), SCALANCE X212-2LD (All versions < V5.2.5), SCALANCE X216 (All versions < V5.2.5), SCALANCE X224 (All versions < V5.2.5), SCALANCE XF201-3P IRT (All versions < 5.5.1), SCALANCE XF202-2P IRT (All versions < 5.5.1), SCALANCE XF204 (All versions < V5.2.5), SCALANCE XF204 IRT (All versions < 5.5.1), SCALANCE XF204-2 (incl. SIPLUS NET variant) (All versions < V5.2.5), SCALANCE XF204-2BA IRT (All versions < 5.5.1), SCALANCE XF206-1 (All versions < V5.2.5), SCALANCE XF208 (All versions < V5.2.5). Incorrect processing of POST requests in the web server may write out of bounds in stack. An attacker might leverage this to denial-of-service of the device or remote code execution.
|
CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): High Integrity (I): High Availibility (A): High | 9.8 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.5 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): High Integrity (I): High Availibility (A): High |
|
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Authentication (Au): None | Impact Metrics: | Confidentiality (C): Partial Integrity (I): Partial Availibility (A): Partial | 10.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Athentication (Au): None
| Impact Metrics: | Confidentiality (C): Complete Integrity (I): Complete Availibility (A): Complete |
|
Vulnerability Type: | CWE-121
|
Vulnerability Consequences: | Gain Access |
References: | Source: MITRE Type: CNA CVE-2021-25669
Source: MISC Type: Patch, Vendor Advisory https://cert-portal.siemens.com/productcert/pdf/ssa-187092.pdf
Source: CCN Type: Siemens Security Advisory SSA-187092 Several Buffer-Overflow Vulnerabilities in Web Server of SCALANCE X-200
Source: XF Type: UNKNOWN siemens-cve202125669-bo(199902)
Source: CCN Type: ICSA-21-103-07 Siemens Web Server of SCALANCE X200
|
Vulnerable Configuration: | Configuration 1: cpe:/o:siemens:scalance_x200-4p_irt_firmware:*:*:*:*:*:*:*:* (Version < 5.5.1)AND cpe:/h:siemens:scalance_x200-4p_irt:-:*:*:*:*:*:*:* Configuration 2: cpe:/o:siemens:scalance_x201-3p_irt_firmware:*:*:*:*:*:*:*:* (Version < 5.5.1)AND cpe:/h:siemens:scalance_x201-3p_irt:-:*:*:*:*:*:*:* Configuration 3: cpe:/o:siemens:scalance_x201-3p_irt_pro_firmware:*:*:*:*:*:*:*:* (Version < 5.5.1)AND cpe:/h:siemens:scalance_x201-3p_irt_pro:-:*:*:*:*:*:*:* Configuration 4: cpe:/o:siemens:scalance_x202-2pirt_firmware:*:*:*:*:*:*:*:* (Version < 5.5.1)AND cpe:/h:siemens:scalance_x202-2_irt:-:*:*:*:*:*:*:* Configuration 5: cpe:/o:siemens:scalance_x202-2p_irt_pro_firmware:*:*:*:*:*:*:*:* (Version < 5.5.1)AND cpe:/h:siemens:scalance_x202-2p_irt_pro:-:*:*:*:*:*:*:* Configuration 6: cpe:/o:siemens:scalance_x204_irt_firmware:*:*:*:*:*:*:*:* (Version < 5.5.1)AND cpe:/h:siemens:scalance_x204_irt:-:*:*:*:*:*:*:* Configuration 7: cpe:/o:siemens:scalance_x204_irt_pro_firmware:*:*:*:*:*:*:*:* (Version < 5.5.1)AND cpe:/h:siemens:scalance_x204_irt_pro:-:*:*:*:*:*:*:* Configuration 8: cpe:/o:siemens:scalance_x204-2_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)AND cpe:/h:siemens:scalance_x204-2:-:*:*:*:*:*:*:* Configuration 9: cpe:/o:siemens:scalance_x204-2fm_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)AND cpe:/h:siemens:scalance_x204-2fm:-:*:*:*:*:*:*:* Configuration 10: cpe:/o:siemens:scalance_x204-2ld_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)AND cpe:/h:siemens:scalance_x204-2ld:-:*:*:*:*:*:*:* Configuration 11: cpe:/o:siemens:scalance_x204-2ld_ts_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)AND cpe:/h:siemens:scalance_x204-2ld_ts:-:*:*:*:*:*:*:* Configuration 12: cpe:/o:siemens:scalance_x204-2ts_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)AND cpe:/h:siemens:scalance_x204-2ts:-:*:*:*:*:*:*:* Configuration 13: cpe:/o:siemens:scalance_x206-1_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)AND cpe:/h:siemens:scalance_x206-1:-:*:*:*:*:*:*:* Configuration 14: cpe:/o:siemens:scalance_x206-1ld_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)AND cpe:/h:siemens:scalance_x206-1ld:-:*:*:*:*:*:*:* Configuration 15: cpe:/o:siemens:scalance_x208_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)AND cpe:/h:siemens:scalance_x208:-:*:*:*:*:*:*:* Configuration 16: cpe:/o:siemens:scalance_x208pro_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)AND cpe:/h:siemens:scalance_x208pro:-:*:*:*:*:*:*:* Configuration 17: cpe:/o:siemens:scalance_x212-2_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)AND cpe:/h:siemens:scalance_x212-2:-:*:*:*:*:*:*:* Configuration 18: cpe:/o:siemens:scalance_x212-2ld_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)AND cpe:/h:siemens:scalance_x212-2ld:-:*:*:*:*:*:*:* Configuration 19: cpe:/o:siemens:scalance_x216_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)AND cpe:/h:siemens:scalance_x216:-:*:*:*:*:*:*:* Configuration 20: cpe:/o:siemens:scalance_x224_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)AND cpe:/h:siemens:scalance_x224:-:*:*:*:*:*:*:* Configuration 21: cpe:/o:siemens:scalance_xf201-3p_irt_firmware:*:*:*:*:*:*:*:* (Version < 5.5.1)AND cpe:/h:siemens:scalance_xf201-3p_irt:-:*:*:*:*:*:*:* Configuration 22: cpe:/o:siemens:scalance_xf202-2p_irt_firmware:*:*:*:*:*:*:*:* (Version < 5.5.1)AND cpe:/h:siemens:scalance_xf202-2p_irt:-:*:*:*:*:*:*:* Configuration 23: cpe:/o:siemens:scalance_xf204_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)AND cpe:/h:siemens:scalance_xf204:-:*:*:*:*:*:*:* Configuration 24: cpe:/o:siemens:scalance_xf204_irt_firmware:*:*:*:*:*:*:*:* (Version < 5.5.1)AND cpe:/h:siemens:scalance_xf204_irt:-:*:*:*:*:*:*:* Configuration 25: cpe:/o:siemens:scalance_xf204-2_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)AND cpe:/h:siemens:scalance_xf204-2:-:*:*:*:*:*:*:* Configuration 26: cpe:/o:siemens:scalance_xf204-2ba_irt_firmware:*:*:*:*:*:*:*:* (Version < 5.5.1)AND cpe:/h:siemens:scalance_xf204-2ba_irt:-:*:*:*:*:*:*:* Configuration 27: cpe:/o:siemens:scalance_xf206-1_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)AND cpe:/h:siemens:scalance_xf206-1:-:*:*:*:*:*:*:* Configuration 28: cpe:/o:siemens:scalance_xf208_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)AND cpe:/h:siemens:scalance_xf208:-:*:*:*:*:*:*:* Configuration 29: cpe:/o:siemens:scalance_x202-2p_irt_firmware:*:*:*:*:*:*:*:* (Version < 5.5.1)AND cpe:/h:siemens:scalance_x202-2p_irt:-:*:*:*:*:*:*:* Configuration CCN 1: cpe:/o:siemens:scalance_x200-4p_irt_firmware:5.5.1:*:*:*:*:*:*:*OR cpe:/o:siemens:scalance_x201-3p_irt_firmware:5.5.1:*:*:*:*:*:*:*OR cpe:/o:siemens:scalance_x201-3p_irt_pro_firmware:5.5.1:*:*:*:*:*:*:*OR cpe:/o:siemens:scalance_x202-2_irt_firmware:5.5.1:*:*:*:*:*:*:*OR cpe:/o:siemens:scalance_x202-2p_irt_pro_firmware:5.5.1:*:*:*:*:*:*:*OR cpe:/o:siemens:scalance_x204_irt_firmware:5.5.1:*:*:*:*:*:*:*OR cpe:/o:siemens:scalance_xf201-3p_irt_firmware:5.5.1:*:*:*:*:*:*:*OR cpe:/o:siemens:scalance_xf202-2p_irt_firmware:5.5.1:*:*:*:*:*:*:*OR cpe:/o:siemens:scalance_xf204_irt_firmware:5.5.1:*:*:*:*:*:*:*OR cpe:/o:siemens:scalance_xf204-2ba_irt_firmware:5.5.1:*:*:*:*:*:*:*
Denotes that component is vulnerable |
BACK |
siemens scalance x200-4p irt firmware *
siemens scalance x200-4p irt -
siemens scalance x201-3p irt firmware *
siemens scalance x201-3p irt -
siemens scalance x201-3p irt pro firmware *
siemens scalance x201-3p irt pro -
siemens scalance x202-2pirt firmware *
siemens scalance x202-2 irt -
siemens scalance x202-2p irt pro firmware *
siemens scalance x202-2p irt pro -
siemens scalance x204 irt firmware *
siemens scalance x204 irt -
siemens scalance x204 irt pro firmware *
siemens scalance x204 irt pro -
siemens scalance x204-2 firmware *
siemens scalance x204-2 -
siemens scalance x204-2fm firmware *
siemens scalance x204-2fm -
siemens scalance x204-2ld firmware *
siemens scalance x204-2ld -
siemens scalance x204-2ld ts firmware *
siemens scalance x204-2ld ts -
siemens scalance x204-2ts firmware *
siemens scalance x204-2ts -
siemens scalance x206-1 firmware *
siemens scalance x206-1 -
siemens scalance x206-1ld firmware *
siemens scalance x206-1ld -
siemens scalance x208 firmware *
siemens scalance x208 -
siemens scalance x208pro firmware *
siemens scalance x208pro -
siemens scalance x212-2 firmware *
siemens scalance x212-2 -
siemens scalance x212-2ld firmware *
siemens scalance x212-2ld -
siemens scalance x216 firmware *
siemens scalance x216 -
siemens scalance x224 firmware *
siemens scalance x224 -
siemens scalance xf201-3p irt firmware *
siemens scalance xf201-3p irt -
siemens scalance xf202-2p irt firmware *
siemens scalance xf202-2p irt -
siemens scalance xf204 firmware *
siemens scalance xf204 -
siemens scalance xf204 irt firmware *
siemens scalance xf204 irt -
siemens scalance xf204-2 firmware *
siemens scalance xf204-2 -
siemens scalance xf204-2ba irt firmware *
siemens scalance xf204-2ba irt -
siemens scalance xf206-1 firmware *
siemens scalance xf206-1 -
siemens scalance xf208 firmware *
siemens scalance xf208 -
siemens scalance x202-2p irt firmware *
siemens scalance x202-2p irt -
siemens scalance x200-4p irt firmware 5.5.1
siemens scalance x201-3p irt firmware 5.5.1
siemens scalance x201-3p irt pro firmware 5.5.1
siemens scalance x202-2 irt firmware 5.5.1
siemens scalance x202-2p irt pro firmware 5.5.1
siemens scalance x204 irt firmware 5.5.1
siemens scalance xf201-3p irt firmware 5.5.1
siemens scalance xf202-2p irt firmware 5.5.1
siemens scalance xf204 irt firmware 5.5.1
siemens scalance xf204-2ba irt firmware 5.5.1