QID 590389

Date Published: 2021-09-07

QID 590389: Siemens SCALANCE S-600 (Update B) Multiple Vulnerabilities (ICSA-20-042-10)

AFFECTED PRODUCTS
The following versions of SCALANCE S-600, are affected:
SCALANCE S602, all versions v3.0 or higher and prior to v4.1
SCALANCE S612, all versions v3.0 or higher and prior to v4.1
SCALANCE S623, all versions v3.0 or higher and prior to v4.1
SCALANCE S627-2M, all versions v3.0 or higher and prior to v4.1

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version using passive scanning

These vulnerabilities could allow a remote attacker to conduct denial-of-service or cross-site scripting attacks. User interaction is required for a successful exploitation of the cross-site-scripting attack.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-20-042-10 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590389

    Software Advisories
    Advisory ID Software Component Link
    ICSA-20-042-10 URL Logo www.us-cert.gov/ics/advisories/ICSA-20-042-10