Vulnerability Name: | CVE-2022-40631 (CCN-238377) |
Assigned: | 2022-10-11 |
Published: | 2022-10-11 |
Updated: | 2022-10-14 |
Summary: | A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < V5.5.0), SCALANCE X201-3P IRT (All versions < V5.5.0), SCALANCE X201-3P IRT PRO (All versions < V5.5.0), SCALANCE X202-2IRT (All versions < V5.5.0), SCALANCE X202-2P IRT (All versions < V5.5.0), SCALANCE X202-2P IRT PRO (All versions < V5.5.0), SCALANCE X204-2 (All versions < V5.2.5), SCALANCE X204-2FM (All versions < V5.2.5), SCALANCE X204-2LD (All versions < V5.2.5), SCALANCE X204-2LD TS (All versions < V5.2.5), SCALANCE X204-2TS (All versions < V5.2.5), SCALANCE X204IRT (All versions < V5.5.0), SCALANCE X204IRT PRO (All versions < V5.5.0), SCALANCE X206-1 (All versions < V5.2.5), SCALANCE X206-1LD (All versions < V5.2.5), SCALANCE X208 (All versions < V5.2.5), SCALANCE X208PRO (All versions < V5.2.5), SCALANCE X212-2 (All versions < V5.2.5), SCALANCE X212-2LD (All versions < V5.2.5), SCALANCE X216 (All versions < V5.2.5), SCALANCE X224 (All versions < V5.2.5), SCALANCE XF201-3P IRT (All versions < V5.5.0), SCALANCE XF202-2P IRT (All versions < V5.5.0), SCALANCE XF204 (All versions < V5.2.5), SCALANCE XF204-2 (All versions < V5.2.5), SCALANCE XF204-2BA IRT (All versions < V5.5.0), SCALANCE XF204IRT (All versions < V5.5.0), SCALANCE XF206-1 (All versions < V5.2.5), SCALANCE XF208 (All versions < V5.2.5), SIPLUS NET SCALANCE X202-2P IRT (All versions < V5.5.0). There is a cross-site scripting vulnerability on the affected devices, that if used by a threat actor, it could result in session hijacking.
|
CVSS v3 Severity: | 6.1 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N) 5.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): Required | Scope: | Scope (S): Changed
| Impact Metrics: | Confidentiality (C): Low Integrity (I): Low Availibility (A): None | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L) 7.0 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:H/RL:O/RC:C)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): Low Integrity (I): Low Availibility (A): Low |
|
CVSS v2 Severity: | 7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Athentication (Au): None
| Impact Metrics: | Confidentiality (C): Partial Integrity (I): Partial Availibility (A): Partial |
|
Vulnerability Type: | CWE-79
|
Vulnerability Consequences: | Denial of Service |
References: | Source: MITRE Type: CNA CVE-2022-40631
Source: CCN Type: Siemens Security Advisory SSA-501891 Cross-Site Scripting Vulnerability in SCALANCE X-200 and X-200IRT Families
Source: MISC Type: Vendor Advisory https://cert-portal.siemens.com/productcert/pdf/ssa-501891.pdf
Source: XF Type: UNKNOWN siemens-scalance-cve202240631-xss(238377)
Source: CCN Type: ICSA-22-286-15 Siemens SCALANCE X-200 and X-200IRT Families
|
Vulnerable Configuration: | Configuration 1: cpe:/o:siemens:scalance_x200-4p_irt_firmware:*:*:*:*:*:*:*:* (Version < 5.5.0)AND cpe:/h:siemens:scalance_x200-4p_irt:-:*:*:*:*:*:*:* Configuration 2: cpe:/o:siemens:scalance_x201-3p_irt_firmware:*:*:*:*:*:*:*:* (Version < 5.5.0)AND cpe:/h:siemens:scalance_x201-3p_irt:-:*:*:*:*:*:*:* Configuration 3: cpe:/o:siemens:scalance_x201-3p_irt_pro_firmware:*:*:*:*:*:*:*:* (Version < 5.5.0)AND cpe:/h:siemens:scalance_x201-3p_irt_pro:-:*:*:*:*:*:*:* Configuration 4: cpe:/o:siemens:scalance_x202-2irt_firmware:*:*:*:*:*:*:*:* (Version < 5.5.0)AND cpe:/h:siemens:scalance_x202-2irt:-:*:*:*:*:*:*:* Configuration 5: cpe:/o:siemens:scalance_x202-2p_irt_firmware:*:*:*:*:*:*:*:* (Version < 5.5.0)AND cpe:/h:siemens:scalance_x202-2p_irt:-:*:*:*:*:*:*:* Configuration 6: cpe:/o:siemens:scalance_x202-2p_irt_pro_firmware:*:*:*:*:*:*:*:* (Version < 5.5.0)AND cpe:/h:siemens:scalance_x202-2p_irt_pro:-:*:*:*:*:*:*:* Configuration 7: cpe:/o:siemens:scalance_x204-2_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)AND cpe:/h:siemens:scalance_x204-2:-:*:*:*:*:*:*:* Configuration 8: cpe:/o:siemens:scalance_x204-2fm_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)AND cpe:/h:siemens:scalance_x204-2fm:-:*:*:*:*:*:*:* Configuration 9: cpe:/o:siemens:scalance_x204-2ld_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)AND cpe:/h:siemens:scalance_x204-2ld:-:*:*:*:*:*:*:* Configuration 10: cpe:/o:siemens:scalance_x204-2ld_ts_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)AND cpe:/h:siemens:scalance_x204-2ld_ts:-:*:*:*:*:*:*:* Configuration 11: cpe:/o:siemens:scalance_x204-2ts_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)AND cpe:/h:siemens:scalance_x204-2ts:-:*:*:*:*:*:*:* Configuration 12: cpe:/o:siemens:scalance_x204irt_firmware:*:*:*:*:*:*:*:* (Version < 5.5.0)AND cpe:/h:siemens:scalance_x204irt:-:*:*:*:*:*:*:* Configuration 13: cpe:/o:siemens:scalance_x204irt_pro_firmware:*:*:*:*:*:*:*:* (Version < 5.5.0)AND cpe:/h:siemens:scalance_x204irt_pro:-:*:*:*:*:*:*:* Configuration 14: cpe:/o:siemens:scalance_x206-1_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)AND cpe:/h:siemens:scalance_x206-1:-:*:*:*:*:*:*:* Configuration 15: cpe:/o:siemens:scalance_x206-1ld_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)AND cpe:/h:siemens:scalance_x206-1ld:-:*:*:*:*:*:*:* Configuration 16: cpe:/o:siemens:scalance_x208_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)AND cpe:/h:siemens:scalance_x208:-:*:*:*:*:*:*:* Configuration 17: cpe:/o:siemens:scalance_x208pro_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)AND cpe:/h:siemens:scalance_x208pro:-:*:*:*:*:*:*:* Configuration 18: cpe:/o:siemens:scalance_x212-2_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)AND cpe:/h:siemens:scalance_x212-2:-:*:*:*:*:*:*:* Configuration 19: cpe:/o:siemens:scalance_x212-2ld_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)AND cpe:/h:siemens:scalance_x212-2ld:-:*:*:*:*:*:*:* Configuration 20: cpe:/o:siemens:scalance_x216_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)AND cpe:/h:siemens:scalance_x216:-:*:*:*:*:*:*:* Configuration 21: cpe:/o:siemens:scalance_x224_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)AND cpe:/h:siemens:scalance_x224:-:*:*:*:*:*:*:* Configuration 22: cpe:/o:siemens:scalance_xf201-3p_irt_firmware:*:*:*:*:*:*:*:* (Version < 5.5.0)AND cpe:/h:siemens:scalance_xf201-3p_irt:-:*:*:*:*:*:*:* Configuration 23: cpe:/o:siemens:scalance_xf202-2p_irt_firmware:*:*:*:*:*:*:*:* (Version < 5.5.0)AND cpe:/h:siemens:scalance_xf202-2p_irt:-:*:*:*:*:*:*:* Configuration 24: cpe:/o:siemens:scalance_xf204_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)AND cpe:/h:siemens:scalance_xf204:-:*:*:*:*:*:*:* Configuration 25: cpe:/o:siemens:scalance_xf204-2_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)AND cpe:/h:siemens:scalance_xf204-2:-:*:*:*:*:*:*:* Configuration 26: cpe:/o:siemens:scalance_xf204-2ba_irt_firmware:*:*:*:*:*:*:*:* (Version < 5.5.0)AND cpe:/h:siemens:scalance_xf204-2ba_irt:-:*:*:*:*:*:*:* Configuration 27: cpe:/o:siemens:scalance_xf204irt_firmware:*:*:*:*:*:*:*:* (Version < 5.5.0)AND cpe:/h:siemens:scalance_xf204irt:-:*:*:*:*:*:*:* Configuration 28: cpe:/o:siemens:scalance_xf206-1_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)AND cpe:/h:siemens:scalance_xf206-1:-:*:*:*:*:*:*:* Configuration 29: cpe:/o:siemens:scalance_xf208_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)AND cpe:/h:siemens:scalance_xf208:-:*:*:*:*:*:*:* Configuration 30: cpe:/o:siemens:siplus_net_scalance_x202-2p_irt_firmware:*:*:*:*:*:*:*:* (Version < 5.5.0)AND cpe:/h:siemens:siplus_net_scalance_x202-2p_irt:-:*:*:*:*:*:*:* Configuration CCN 1: cpe:/h:siemens:scalance_x200-4p_irt:-:*:*:*:*:*:*:*OR cpe:/h:siemens:scalance_x201-3p_irt:-:*:*:*:*:*:*:*OR cpe:/h:siemens:scalance_x202-2irt:-:*:*:*:*:*:*:*OR cpe:/h:siemens:scalance_x202-2p_irt:-:*:*:*:*:*:*:*OR cpe:/h:siemens:scalance_x204irt:-:*:*:*:*:*:*:*OR cpe:/h:siemens:scalance_x200-4p_irt:-:*:*:*:*:*:*:*OR cpe:/h:siemens:scalance_x201-3p_irt:-:*:*:*:*:*:*:*OR cpe:/h:siemens:scalance_x201-3p_irt:-:-:pro:*:*:*:*:*OR cpe:/h:siemens:scalance_x202-2irt:-:*:*:*:*:*:*:*OR cpe:/h:siemens:scalance_x202-2p_irt:-:*:*:*:*:*:*:*OR cpe:/h:siemens:scalance_x202-2p_irt:-:-:pro:*:*:*:*:*OR cpe:/h:siemens:scalance_x204-2:-:*:*:*:*:*:*:*OR cpe:/h:siemens:scalance_x204-2fm:-:*:*:*:*:*:*:*OR cpe:/h:siemens:scalance_x204-2ld:-:*:*:*:*:*:*:*OR cpe:/h:siemens:scalance_x204-2ld_ts:-:*:*:*:*:*:*:*OR cpe:/h:siemens:scalance_x204-2ts:-:*:*:*:*:*:*:*OR cpe:/h:siemens:scalance_x204irt:-:*:*:*:*:*:*:*OR cpe:/h:siemens:scalance_x204irt:-:*:*:*:*:*:*:*OR cpe:/h:siemens:scalance_x206-1:-:*:*:*:*:*:*:*OR cpe:/h:siemens:scalance_x206-1:-:*:*:*:*:*:*:*OR cpe:/h:siemens:scalance_x208:-:*:*:*:*:*:*:*OR cpe:/h:siemens:scalance_x208pro:-:*:*:*:*:*:*:*OR cpe:/h:siemens:scalance_x212-2:-:*:*:*:*:*:*:*OR cpe:/h:siemens:scalance_x212-2ld:-:*:*:*:*:*:*:*OR cpe:/h:siemens:scalance_x216:-:*:*:*:*:*:*:*OR cpe:/h:siemens:scalance_x224:-:*:*:*:*:*:*:*OR cpe:/h:siemens:scalance_xf204:-:*:*:*:*:*:*:*OR cpe:/h:siemens:scalance_xf204-2:-:*:*:*:*:*:*:*OR cpe:/h:siemens:scalance_xf204-2ba_irt:-:*:*:*:*:*:*:*OR cpe:/h:siemens:scalance_xf204irt:-:*:*:*:*:*:*:*OR cpe:/h:siemens:scalance_xf206-1:-:*:*:*:*:*:*:*OR cpe:/h:siemens:scalance_xf208:-:*:*:*:*:*:*:*
Denotes that component is vulnerable |
BACK |
siemens scalance x200-4p irt firmware *
siemens scalance x200-4p irt -
siemens scalance x201-3p irt firmware *
siemens scalance x201-3p irt -
siemens scalance x201-3p irt pro firmware *
siemens scalance x201-3p irt pro -
siemens scalance x202-2irt firmware *
siemens scalance x202-2irt -
siemens scalance x202-2p irt firmware *
siemens scalance x202-2p irt -
siemens scalance x202-2p irt pro firmware *
siemens scalance x202-2p irt pro -
siemens scalance x204-2 firmware *
siemens scalance x204-2 -
siemens scalance x204-2fm firmware *
siemens scalance x204-2fm -
siemens scalance x204-2ld firmware *
siemens scalance x204-2ld -
siemens scalance x204-2ld ts firmware *
siemens scalance x204-2ld ts -
siemens scalance x204-2ts firmware *
siemens scalance x204-2ts -
siemens scalance x204irt firmware *
siemens scalance x204irt -
siemens scalance x204irt pro firmware *
siemens scalance x204irt pro -
siemens scalance x206-1 firmware *
siemens scalance x206-1 -
siemens scalance x206-1ld firmware *
siemens scalance x206-1ld -
siemens scalance x208 firmware *
siemens scalance x208 -
siemens scalance x208pro firmware *
siemens scalance x208pro -
siemens scalance x212-2 firmware *
siemens scalance x212-2 -
siemens scalance x212-2ld firmware *
siemens scalance x212-2ld -
siemens scalance x216 firmware *
siemens scalance x216 -
siemens scalance x224 firmware *
siemens scalance x224 -
siemens scalance xf201-3p irt firmware *
siemens scalance xf201-3p irt -
siemens scalance xf202-2p irt firmware *
siemens scalance xf202-2p irt -
siemens scalance xf204 firmware *
siemens scalance xf204 -
siemens scalance xf204-2 firmware *
siemens scalance xf204-2 -
siemens scalance xf204-2ba irt firmware *
siemens scalance xf204-2ba irt -
siemens scalance xf204irt firmware *
siemens scalance xf204irt -
siemens scalance xf206-1 firmware *
siemens scalance xf206-1 -
siemens scalance xf208 firmware *
siemens scalance xf208 -
siemens siplus net scalance x202-2p irt firmware *
siemens siplus net scalance x202-2p irt -
siemens scalance x200-4p irt -
siemens scalance x201-3p irt -
siemens scalance x202-2irt -
siemens scalance x202-2p irt -
siemens scalance x204irt -
siemens scalance x200-4p irt -
siemens scalance x201-3p irt -
siemens scalance x201-3p irt - -
siemens scalance x202-2irt -
siemens scalance x202-2p irt -
siemens scalance x202-2p irt - -
siemens scalance x204-2 -
siemens scalance x204-2fm -
siemens scalance x204-2ld -
siemens scalance x204-2ld ts -
siemens scalance x204-2ts -
siemens scalance x204irt -
siemens scalance x204irt -
siemens scalance x206-1 -
siemens scalance x206-1 -
siemens scalance x208 -
siemens scalance x208pro -
siemens scalance x212-2 -
siemens scalance x212-2ld -
siemens scalance x216 -
siemens scalance x224 -
siemens scalance xf204 -
siemens scalance xf204-2 -
siemens scalance xf204-2ba irt -
siemens scalance xf204irt -
siemens scalance xf206-1 -
siemens scalance xf208 -