Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-56475
HistoryAug 09, 2022 - 12:00 a.m.

Siemens SCALANCE products have unspecified vulnerabilities

2022-08-0900:00:00
China National Vulnerability Database
www.cnvd.org.cn
12
siemens
scalance
ssl/tls
vulnerability
remote access
wireless communication
industrial routers
firewall
vpn
denial-of-service

0.002 Low

EPSS

Percentile

55.2%

SCALANCE M-800, MUM-800 and S615 and RUGGEDCOM RM1224 industrial routers are used for secure remote access to plants over mobile networks (e.g. GPRS or UMTS) with integrated security features of firewalls to prevent unauthorized access, and VPNs to protect data transmission.SCALANCE SC-600 devices (SC622-2C, SC632-2C, SC636-2C, SC642-2C, SC646-2C) are used to protect trusted industrial networks from untrusted network attacks. They allow filtering of incoming and outgoing network connections in different ways.SCALANCE W-1700 products are wireless communication devices based on the IEEE 802.11ac standard.SCALANCE W-700 products are wireless communication devices based on the IEEE 802.11ax standard.SCALANCE X switches are used to connect industrial components such as Programmable logic controllers (PLCs) or human-machine interfaces (HMIs). a security vulnerability exists in Siemens SCALANCE products due to a failure of the affected device to properly handle the renegotiation of SSL/TLS parameters. The vulnerability allows an unauthenticated remote attacker to bypass TCP brute-force prevention and cause a denial-of-service condition during the attack.

0.002 Low

EPSS

Percentile

55.2%

Related for CNVD-2022-56475