CVE-2020-28393
Published on: 05/12/2021 12:00:00 AM UTC
Last Modified on: 05/21/2021 02:03:00 PM UTC
Certain versions of Scalance Xm-400 from Siemens contain the following vulnerability:
An unauthenticated remote attacker could create a permanent denial-of-service condition by sending specially crafted OSPF packets. Successful exploitation requires OSPF to be enabled on an affected device on the SCALANCE XM-400, XR-500 (All versions prior to v6.4).
- CVE-2020-28393 has been assigned by
productc[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 7.5 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | NONE | HIGH |
CVSS2 Score: 7.1 - HIGH
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | NONE | COMPLETE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
cert-portal.siemens.com application/pdf |
![]() | |
Siemens SCALANCE XM-400 and XR-500 Devices | CISA | us-cert.cisa.gov text/html |
![]() |
Related QID Numbers
- 590677 Siemens SCALANCE XM-400 and XR-500 Devices Vulnerability (ICSA-21-131-10)
Known Affected Configurations (CPE V2.3)
- cpe:2.3:h:siemens:scalance_xm-400:-:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:scalance_xm-400_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:scalance_xm408-4c:-:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:scalance_xm408-4c_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:scalance_xm408-4c_l3:-:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:scalance_xm408-4c_l3_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:scalance_xm408-8c:-:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:scalance_xm408-8c_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:scalance_xm408-8c_l3:-:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:scalance_xm408-8c_l3_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:scalance_xm416-4c:-:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:scalance_xm416-4c_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:scalance_xm416-4c_l3:-:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:scalance_xm416-4c_l3_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:scalance_xr524:-:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:scalance_xr524_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:scalance_xr526:-:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:scalance_xr526_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:scalance_xr528:-:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:scalance_xr528_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:siemens:scalance_xr552:-:*:*:*:*:*:*:*:
- cpe:2.3:o:siemens:scalance_xr552_firmware:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2020-28393 : A vulnerability has been identified in SCALANCE XM-400 Family All versions < V6.4 , SCALANCE XR-5… twitter.com/i/web/status/1… | 2021-05-12 13:23:59 |
![]() |
CVE-2020-28393 | 2021-05-12 13:41:03 |