QID 590670

Date Published: 2022-03-17

QID 590670: Siemens SCALANCE and RUGGEDCOM Devices (Update A) Vulnerability (ICSA-21-068-03)

AFFECTED PRODUCTS
The following Siemens products are affected:
RUGGEDCOM RM1224: All versions from v4.3 and prior to v4.6
SCALANCE M-800: All versions from v4.3 and prior to v4.6
SCALANCE S615: All versions from v4.3 and prior to v4.6
SCALANCE XR-300WG: All versions prior to v4.1
SCALANCE XB-200: All versions prior to v4.1
SCALANCE XC-200: All versions prior to v4.1
SCALANCE XF-200BA: All versions prior to v4.1
SCALANCE XP-200: All versions prior to v4.1
SCALANCE SC-600 Family: All versions from v2.0 and prior to v2.1.3
SCALANCE XM400: All versions prior to v6.2
SCALANCE XR500: All versions prior to v6.2

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of this vulnerability could allow an attacker to cause a reboot. Under specific circumstances, an attacker could also achieve remote code execution of the affected devices.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-21-068-03 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590670

    Software Advisories
    Advisory ID Software Component Link
    ICSA-21-068-03 URL Logo www.us-cert.gov/ics/advisories/ICSA-21-068-03