CVE-2022-31766
Summary
| CVE | CVE-2022-31766 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-10-11 11:15:00 UTC |
| Updated | 2023-11-07 03:47:00 UTC |
| Description | A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (All versions < V7.1.2), RUGGEDCOM RM1224 LTE(4G) NAM (All versions < V7.1.2), SCALANCE M804PB (All versions < V7.1.2), SCALANCE M812-1 ADSL-Router (Annex A) (All versions < V7.1.2), SCALANCE M812-1 ADSL-Router (Annex B) (All versions < V7.1.2), SCALANCE M816-1 ADSL-Router (Annex A) (All versions < V7.1.2), SCALANCE M816-1 ADSL-Router (Annex B) (All versions < V7.1.2), SCALANCE M826-2 SHDSL-Router (All versions < V7.1.2), SCALANCE M874-2 (All versions < V7.1.2), SCALANCE M874-3 (All versions < V7.1.2), SCALANCE M876-3 (EVDO) (All versions < V7.1.2), SCALANCE M876-3 (ROK) (All versions < V7.1.2), SCALANCE M876-4 (All versions < V7.1.2), SCALANCE M876-4 (EU) (All versions < V7.1.2), SCALANCE M876-4 (NAM) (All versions < V7.1.2), SCALANCE MUM853-1 (EU) (All versions < V7.1.2), SCALANCE MUM856-1 (EU) (All versions < V7.1.2), SCALANCE MUM856-1 (RoW) (All versions < V7.1.2), SCALANCE S615 (All versions < V7.1.2), SCALANCE S615 EEC (All versions < V7.1.2), SCALANCE WAM763-1 (All versions >= V1.1.0 < V2.0), SCALANCE WAM766-1 (EU) (All versions >= V1.1.0 < V2.0), SCALANCE WAM766-1 (US) (All versions >= V1.1.0 < V2.0), SCALANCE WAM766-1 EEC (EU) (All versions >= V1.1.0 < V2.0), SCALANCE WAM766-1 EEC (US) (All versions >= V1.1.0 < V2.0), SCALANCE WUM763-1 (All versions >= V1.1.0 < V2.0), SCALANCE WUM763-1 (All versions >= V1.1.0 < V2.0), SCALANCE WUM766-1 (EU) (All versions >= V1.1.0 < V2.0), SCALANCE WUM766-1 (US) (All versions >= V1.1.0 < V2.0). Affected devices with TCP Event service enabled do not properly handle malformed packets. This could allow an unauthenticated remote attacker to cause a denial of service condition and reboot the device thus possibly affecting other network resources. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Siemens | Ruggedcom Rm1224 | - | All | All | All |
| Operating System | Siemens | Ruggedcom Rm1224 Firmware | All | All | All | All |
| Hardware | Siemens | Scalance M804pb | - | All | All | All |
| Operating System | Siemens | Scalance M804pb Firmware | All | All | All | All |
| Hardware | Siemens | Scalance M812-1 | - | All | All | All |
| Operating System | Siemens | Scalance M812-1 Firmware | All | All | All | All |
| Hardware | Siemens | Scalance M816-1 | - | All | All | All |
| Operating System | Siemens | Scalance M816-1 Firmware | All | All | All | All |
| Hardware | Siemens | Scalance M826-2 | - | All | All | All |
| Operating System | Siemens | Scalance M826-2 Firmware | All | All | All | All |
| Hardware | Siemens | Scalance M874-2 | - | All | All | All |
| Operating System | Siemens | Scalance M874-2 Firmware | All | All | All | All |
| Hardware | Siemens | Scalance M874-3 | - | All | All | All |
| Operating System | Siemens | Scalance M874-3 Firmware | All | All | All | All |
| Hardware | Siemens | Scalance M876-3 | - | All | All | All |
| Operating System | Siemens | Scalance M876-3 Firmware | All | All | All | All |
| Hardware | Siemens | Scalance M876-4 | - | All | All | All |
| Operating System | Siemens | Scalance M876-4 Firmware | All | All | All | All |
| Hardware | Siemens | Scalance Mum853-1 | - | All | All | All |
| Operating System | Siemens | Scalance Mum853-1 Firmware | All | All | All | All |
| Hardware | Siemens | Scalance Mum856-1 | - | All | All | All |
| Operating System | Siemens | Scalance Mum856-1 Firmware | All | All | All | All |
| Hardware | Siemens | Scalance S615 | - | All | All | All |
| Operating System | Siemens | Scalance S615 Firmware | All | All | All | All |
| Hardware | Siemens | Scalance Wam763-1 | - | All | All | All |
| Operating System | Siemens | Scalance Wam763-1 Firmware | All | All | All | All |
| Hardware | Siemens | Scalance Wam766-1 | - | All | All | All |
| Hardware | Siemens | Scalance Wam766-1 | - | All | All | All |
| Operating System | Siemens | Scalance Wam766-1 Firmware | All | All | All | All |
| Operating System | Siemens | Scalance Wam766-1 Firmware | All | All | All | All |
| Hardware | Siemens | Scalance Wum763-1 | - | All | All | All |
| Operating System | Siemens | Scalance Wum763-1 Firmware | All | All | All | All |
| Hardware | Siemens | Scalance Wum766-1 | - | All | All | All |
| Operating System | Siemens | Scalance Wum766-1 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| cert-portal.siemens.com/productcert/pdf/ssa-697140.pdf | MISC | cert-portal.siemens.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 591291 Siemens SCALANCE and RUGGEDCOM Products Denial of Service (DoS) Vulnerability (ICSA-22-286-08, SSA-697140)