Lucene search

K
cveSiemensCVE-2022-46353
HistoryDec 13, 2022 - 4:15 p.m.

CVE-2022-46353

2022-12-1316:15:25
CWE-330
siemens
web.nvd.nist.gov
29
vulnerability
scalance x204rna
eec
webserver
cve-2022-46353
session hijacking
remote attacker
nvd

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.003

Percentile

72.0%

A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). The webserver of affected devices calculates session ids and nonces in an insecure manner. This could allow an unauthenticated remote attacker to brute-force session ids and hijack existing sessions.

Affected configurations

Nvd
Node
siemens6gk5204-0ba00-2mb2Match-
AND
siemens6gk5204-0ba00-2mb2_firmwareRange<3.2.7
Node
siemens6gk5204-0ba00-2kb2Match-
AND
siemens6gk5204-0ba00-2kb2_firmwareRange<3.2.7
Node
siemens6gk5204-0bs00-2na3Match-
AND
siemens6gk5204-0bs00-2na3_firmwareRange<3.2.7
Node
siemens6gk5204-0bs00-3la3Match-
AND
siemens6gk5204-0bs00-3la3_firmwareRange<3.2.7
Node
siemens6gk5204-0bs00-3pa3Match-
AND
siemens6gk5204-0bs00-3pa3_firmwareRange<3.2.7
VendorProductVersionCPE
siemens6gk5204-0ba00-2mb2-cpe:2.3:h:siemens:6gk5204-0ba00-2mb2:-:*:*:*:*:*:*:*
siemens6gk5204-0ba00-2mb2_firmware*cpe:2.3:o:siemens:6gk5204-0ba00-2mb2_firmware:*:*:*:*:*:*:*:*
siemens6gk5204-0ba00-2kb2-cpe:2.3:h:siemens:6gk5204-0ba00-2kb2:-:*:*:*:*:*:*:*
siemens6gk5204-0ba00-2kb2_firmware*cpe:2.3:o:siemens:6gk5204-0ba00-2kb2_firmware:*:*:*:*:*:*:*:*
siemens6gk5204-0bs00-2na3-cpe:2.3:h:siemens:6gk5204-0bs00-2na3:-:*:*:*:*:*:*:*
siemens6gk5204-0bs00-2na3_firmware*cpe:2.3:o:siemens:6gk5204-0bs00-2na3_firmware:*:*:*:*:*:*:*:*
siemens6gk5204-0bs00-3la3-cpe:2.3:h:siemens:6gk5204-0bs00-3la3:-:*:*:*:*:*:*:*
siemens6gk5204-0bs00-3la3_firmware*cpe:2.3:o:siemens:6gk5204-0bs00-3la3_firmware:*:*:*:*:*:*:*:*
siemens6gk5204-0bs00-3pa3-cpe:2.3:h:siemens:6gk5204-0bs00-3pa3:-:*:*:*:*:*:*:*
siemens6gk5204-0bs00-3pa3_firmware*cpe:2.3:o:siemens:6gk5204-0bs00-3pa3_firmware:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Siemens",
    "product": "SCALANCE X204RNA (HSR)",
    "versions": [
      {
        "version": "All versions < V3.2.7",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Siemens",
    "product": "SCALANCE X204RNA (PRP)",
    "versions": [
      {
        "version": "All versions < V3.2.7",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Siemens",
    "product": "SCALANCE X204RNA EEC (HSR)",
    "versions": [
      {
        "version": "All versions < V3.2.7",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Siemens",
    "product": "SCALANCE X204RNA EEC (PRP)",
    "versions": [
      {
        "version": "All versions < V3.2.7",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Siemens",
    "product": "SCALANCE X204RNA EEC (PRP/HSR)",
    "versions": [
      {
        "version": "All versions < V3.2.7",
        "status": "affected"
      }
    ]
  }
]

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.003

Percentile

72.0%

Related for CVE-2022-46353